Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-01-30 CVE-2024-13642 Cross-site Scripting vulnerability in Motopress Stratum
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
motopress CWE-79
5.4
2025-01-30 CVE-2024-12921 The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2025-01-30 CVE-2025-23374 Information Exposure Through Log Files vulnerability in Dell Enterprise Sonic Distribution
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability.
network
low complexity
dell CWE-532
4.9
2025-01-30 CVE-2025-0847 SQL Injection vulnerability in 1000Projects Employee Task Management System 1.0
A vulnerability was found in 1000 Projects Employee Task Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2025-01-30 CVE-2025-0848 Stack-based Buffer Overflow vulnerability in Tenda A18 Firmware 15.13.07.09
A vulnerability was found in Tenda A18 up to 15.13.07.09.
network
low complexity
tenda CWE-121
critical
9.8
2025-01-30 CVE-2025-0849 Unspecified vulnerability in Campcodes School Management Software 1.0
A vulnerability classified as critical has been found in CampCodes School Management Software 1.0.
network
low complexity
campcodes
8.1
2025-01-30 CVE-2025-0846 SQL Injection vulnerability in 1000Projects Employee Task Management System 1.0
A vulnerability was found in 1000 Projects Employee Task Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2025-01-30 CVE-2025-0844 Cross-site Scripting vulnerability in Needyamin Library Card System 1.0
A vulnerability was found in needyamin Library Card System 1.0.
network
low complexity
needyamin CWE-79
6.1
2025-01-29 CVE-2025-0843 SQL Injection vulnerability in Needyamin Library Card System 1.0
A vulnerability was found in needyamin Library Card System 1.0.
network
low complexity
needyamin CWE-89
critical
9.8
2025-01-29 CVE-2025-21396 Unspecified vulnerability in Microsoft Account
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
microsoft
8.2