Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-4022 | A vulnerability was found in web-arena-x webarena up to 0.2.0. A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the argument target["url"] leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC ×2 |
| — | |
| CVE-2024-12463 | The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'arena_embed_amp' shortcode The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'arena_embed_amp' shortcode in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2020-27384 | The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to mod The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2021-29930 +1 in the same advisory: …29931 | An issue was discovered in the arenavec crate through 2021-01-12 for Rust. An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A drop of uninitialized memory can sometimes occur upon a panic in T::default(). NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2021-28032 | An issue was discovered in the nano_arena crate before 0.5.2 for Rust. An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at because two mutable references can exist for the same element, if Borrow behaves in certain ways. This can have a resultant out-of-bounds write or use-after-free. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2019-16139 | An issue was discovered in the compact_arena crate before 0.4.0 for Rust. An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2018-17398 | SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter. SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — |