Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-07 CVE-2024-7425 Code Injection vulnerability in Soflyy WP ALL Export 1.7.9/1.8.6
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1.
network
low complexity
soflyy CWE-94
7.2
2025-02-07 CVE-2025-1104 A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical.
network
low complexity
CWE-290
7.3
2025-02-07 CVE-2024-7419 Code Injection vulnerability in Soflyy WP ALL Export 1.7.9/1.8.6
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields.
network
low complexity
soflyy CWE-94
8.8
2025-02-07 CVE-2024-9664 Deserialization of Untrusted Data vulnerability in Soflyy WP ALL Import
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file.
network
low complexity
soflyy CWE-502
7.2
2025-02-07 CVE-2025-0302 Integer Overflow or Wraparound vulnerability in Openatom Openharmony 4.1.0/4.1.1
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
local
low complexity
openatom CWE-190
5.5
2025-02-07 CVE-2025-0303 Classic Buffer Overflow vulnerability in Openatom Openharmony 4.1.0/4.1.1
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.
local
low complexity
openatom CWE-120
7.8
2025-02-07 CVE-2025-0304 Use After Free vulnerability in Openatom Openharmony 4.1.0/4.1.1
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
local
low complexity
openatom CWE-416
7.8
2025-02-07 CVE-2025-25160 Cross-Site Request Forgery (CSRF) vulnerability in Markbarnes Style Tweaker
Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker allows Stored XSS.
network
low complexity
markbarnes CWE-352
6.1
2025-02-07 CVE-2025-25163 Path Traversal vulnerability in Pluginab Plugin A/B Image Optimizer
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer allows Path Traversal.
network
low complexity
pluginab CWE-22
critical
9.8
2025-02-07 CVE-2025-25166 Cross-Site Request Forgery (CSRF) vulnerability in Gabrieldarezzo Inlocation
Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation allows Stored XSS.
network
low complexity
gabrieldarezzo CWE-352
6.1