Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-17 CVE-2017-13322 Unspecified vulnerability in Google Android
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code.
local
low complexity
google
5.5
2025-01-17 CVE-2025-0538 Cross-site Scripting vulnerability in Fabianros Tourism Management System 1.0
A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0.
network
low complexity
fabianros CWE-79
4.8
2025-01-17 CVE-2025-0537 Cross-site Scripting vulnerability in Fabianros Online CAR Rental System 1.0
A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0.
network
low complexity
fabianros CWE-79
4.8
2025-01-17 CVE-2025-21185 Unspecified vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
network
low complexity
microsoft
6.5
2025-01-17 CVE-2025-0531 A vulnerability was found in code-projects Chat System 1.0 and classified as critical.
network
low complexity
CWE-74
6.3
2025-01-17 CVE-2025-0529 A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0.
local
low complexity
CWE-121
5.3
2025-01-17 CVE-2024-13378 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping.
network
high complexity
CWE-79
5.4
2025-01-17 CVE-2024-12370 Missing Authorization vulnerability in Thimpress WP Hotel Booking
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5.
network
low complexity
thimpress CWE-862
5.3
2025-01-17 CVE-2024-12203 The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping.
network
high complexity
CWE-79
4.4
2025-01-17 CVE-2024-12466 The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.2.1.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1