Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2025-0974 A vulnerability, which was classified as critical, has been found in MaxD Lightning Module 4.43 on OpenCart.
network
high complexity
CWE-502
5.0
2025-02-03 CVE-2025-0973 Path Traversal vulnerability in Cmseasy 7.7.7.9
A vulnerability classified as critical was found in CmsEasy 7.7.7.9.
network
low complexity
cmseasy CWE-22
6.5
2025-02-03 CVE-2025-0971 A vulnerability was found in Zenvia Movidesk up to 25.01.22.
network
low complexity
CWE-94
3.5
2025-02-03 CVE-2025-0972 A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22.
network
low complexity
CWE-94
3.5
2025-02-02 CVE-2025-0970 A vulnerability was found in Zenvia Movidesk up to 25.01.22.
network
low complexity
CWE-601
4.3
2025-02-02 CVE-2025-0967 SQL Injection vulnerability in Fabianros Chat System 1.0
A vulnerability was found in code-projects Chat System 1.0 and classified as critical.
network
low complexity
fabianros CWE-89
7.5
2025-02-01 CVE-2025-0947 A vulnerability, which was classified as critical, has been found in itsourcecode Tailoring Management System 1.0.
network
low complexity
CWE-74
6.3
2025-02-01 CVE-2025-0946 SQL Injection vulnerability in Angeljudesuarez Tailoring Management System 1.0
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2025-02-01 CVE-2025-0945 SQL Injection vulnerability in Angeljudesuarez Tailoring Management System 1.0
A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2025-02-01 CVE-2024-13612 Cross-site Scripting vulnerability in Wordplus Better Messages
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wordplus CWE-79
5.4