Show filters
590 Total Results
Displaying 1-10 of 590
Sort by:
Attacker Value
Unknown
CVE-2025-27106
Disclosure Date: February 21, 2025 (last updated February 23, 2025)
binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of binance-trading-bot is vulnerable to command injection via the `/restore` endpoint. The name of the uploaded file is passed to shell.exec without sanitization other than path normalization, resulting in Remote Code Execution. This may allow any authorized user to execute code in the context of the host machine. This issue has been addressed in version 0.0.100 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2025-23975
Disclosure Date: February 16, 2025 (last updated February 17, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Botnet Attack Blocker allows Stored XSS. This issue affects Botnet Attack Blocker: from n/a through 2.0.0.
0
Attacker Value
Unknown
CVE-2025-0522
Disclosure Date: February 06, 2025 (last updated February 06, 2025)
The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
0
Attacker Value
Unknown
CVE-2024-49834
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while power-up or power-down sequence of the camera sensor.
0
Attacker Value
Unknown
CVE-2024-38420
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while configuring a Hypervisor based input virtual device.
0
Attacker Value
Unknown
CVE-2025-24666
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeIsle AI Chatbot for WordPress – Hyve Lite allows Stored XSS. This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 1.2.2.
0
Attacker Value
Unknown
CVE-2024-52331
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
0
Attacker Value
Unknown
CVE-2024-52330
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
0
Attacker Value
Unknown
CVE-2024-52328
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
0
Attacker Value
Unknown
CVE-2024-12079
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.
0