Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-12-22 CVE-2024-12894 SQL Injection vulnerability in Treasurehuntgame Treasurehunt
A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0.
network
low complexity
treasurehuntgame CWE-89
critical
9.8
2024-12-22 CVE-2024-12892 Unspecified vulnerability in Code-Projects Online Exam Mastering System 1.0
A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0.
network
low complexity
code-projects
5.4
2024-12-22 CVE-2024-12891 Unspecified vulnerability in Code-Projects Online Exam Mastering System 1.0
A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0.
network
low complexity
code-projects
8.8
2024-12-22 CVE-2024-12890 Unspecified vulnerability in Code-Projects Online Exam Mastering System 1.0
A vulnerability was found in code-projects Online Exam Mastering System 1.0.
network
low complexity
code-projects
8.8
2024-12-22 CVE-2024-11852 Missing Authorization vulnerability in Bdthemes Element Pack
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12.
network
low complexity
bdthemes CWE-862
4.3
2024-12-21 CVE-2024-12884 SQL Injection vulnerability in Codezips E-Commerce Site 1.0
A vulnerability was found in Codezips E-Commerce Website 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-12-21 CVE-2024-51463 IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF).
network
low complexity
CWE-918
5.4
2024-12-21 CVE-2024-12883 Cross-site Scripting vulnerability in Anisha JOB Recruitment 1.0
A vulnerability was found in code-projects Job Recruitment 1.0.
network
low complexity
anisha CWE-79
6.1
2024-12-21 CVE-2024-12875 Path Traversal vulnerability in Awesomemotive Easy Digital Downloads
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality.
network
low complexity
awesomemotive CWE-22
4.9
2024-12-21 CVE-2024-10453 Cross-site Scripting vulnerability in Elementor Website Builder
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
elementor CWE-79
5.4