Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-01-24 CVE-2025-0704 A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d.
network
low complexity
CWE-400
5.3
2025-01-24 CVE-2025-0705 A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic.
network
low complexity
CWE-601
4.3
2025-01-24 CVE-2024-35122 IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement.
local
low complexity
CWE-284
2.8
2025-01-24 CVE-2025-0702 A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d.
network
low complexity
CWE-434
6.3
2025-01-24 CVE-2025-24578 Cross-site Scripting vulnerability in Elementinvader Addons for Elementor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows DOM-Based XSS.
network
low complexity
elementinvader CWE-79
5.4
2025-01-24 CVE-2025-24591 Missing Authorization vulnerability in Ninjateam Gdpr Ccpa Compliance & Cookie Consent Banner
Missing Authorization vulnerability in NinjaTeam GDPR CCPA Compliance Support allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
ninjateam CWE-862
8.8
2025-01-24 CVE-2025-24596 Missing Authorization vulnerability in Wcproducttable Woocommerce Product Table
Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
wcproducttable CWE-862
critical
9.8
2025-01-24 CVE-2025-24618 Missing Authorization vulnerability in Elementinvader Addons for Elementor
Missing Authorization vulnerability in ElementInvader ElementInvader Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
elementinvader CWE-862
8.8
2025-01-24 CVE-2025-24644 Cross-site Scripting vulnerability in Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stored XSS.
network
low complexity
webtoffee CWE-79
4.8
2025-01-24 CVE-2025-24727 Cross-site Scripting vulnerability in Codepeople Contact Form Email
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Contact Form Email allows Stored XSS.
network
low complexity
codepeople CWE-79
4.8