Show filters
346 Total Results
Displaying 21-30 of 346
Sort by:
Attacker Value
Unknown
CVE-2024-21924
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-0179
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-20507
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.
0
Attacker Value
Unknown
CVE-2025-25081
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Missing Authorization vulnerability in DeannaS Embed RSS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Embed RSS: from n/a through 3.1.
0
Attacker Value
Unknown
CVE-2025-25078
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrew Norcross Google Earth Embed allows Stored XSS. This issue affects Google Earth Embed: from n/a through 1.0.
0
Attacker Value
Unknown
CVE-2025-22696
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
Missing Authorization vulnerability in EmbedPress Document Block – Upload & Embed Docs. This issue affects Document Block – Upload & Embed Docs: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-13700
Disclosure Date: January 30, 2025 (last updated February 01, 2025)
The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2025-0747
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that will be executed when a user opens the chat.
0
Attacker Value
Unknown
CVE-2025-0746
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the malicious URL.
0
Attacker Value
Unknown
CVE-2025-0745
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the "/embedai/app/uploads/database/<SQL_FILE>" endpoint.
0