-
CVE-2024-23973 – Silicon Labs Gecko OS HTTP GET Request Buffer Overflow Allows Arbitrary Code Execution over the Network
CVE ID : CVE-2024-23973 Published : Jan. 31, 2025, 12:15 a.m. | 1 day, 3 hours ago Description : This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HTTP GET requests. The issue…
-
CVE-2024-23969 – ChargePoint Home Flex Rce (Buffer Overflow)
CVE ID : CVE-2024-23969 Published : Jan. 31, 2025, 12:15 a.m. | 1 day, 3 hours ago Description : This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue results from…
-
CVE-2024-23963 – Alpine Halo9 Bluetooth PBAP Code Execution Vulnerability
CVE ID : CVE-2024-23963 Published : Jan. 31, 2025, 12:15 a.m. | 1 day, 3 hours ago Description : This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this…
-
CVE-2024-23968 – ChargePoint Home Flex Stack Based Buffer Overflow
CVE ID : CVE-2024-23968 Published : Jan. 31, 2025, 12:15 a.m. | 1 day, 3 hours ago Description : This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue results from…
-
CVE-2024-23928 – Pioneer DMH-WT7600NEX Certificate Validation Vulnerability
CVE ID : CVE-2024-23928 Published : Jan. 31, 2025, 12:15 a.m. | 1 day, 3 hours ago Description : This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the telematics functionality, which operates over…
-
CVE-2025-0804 – WordPress ClickWhale Link Manager Stored XSS
CVE ID : CVE-2025-0804 Published : Jan. 29, 2025, 4:15 a.m. | 2 hours, 46 minutes ago Description : The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to…
-
CVE-2024-12749 – WordPress Competition Form XSS Vulnerability
CVE ID : CVE-2024-12749 Published : Jan. 29, 2025, 6:15 a.m. | 45 minutes ago Description : The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. Severity:…
-
CVE-2025-23362 – Adobe EXIF Viewer Classic Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-23362 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed…
-
CVE-2025-0806 – Code-projects Job Recruitment Cross Site Scripting Vulnerability
CVE ID : CVE-2025-0806 Published : Jan. 29, 2025, 3:15 a.m. | 3 hours, 46 minutes ago Description : A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of the argument job_type leads to cross site scripting. The attack…
-
CVE-2025-0802 – SourceCodester Best Employee Management System Remote Improper Access Control Vulnerability
CVE ID : CVE-2025-0802 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls.…