2024-12-22 | CVE-2024-12890 | Unspecified vulnerability in Code-Projects Online Exam Mastering System 1.0 A vulnerability was found in code-projects Online Exam Mastering System 1.0. | 8.8 |
2024-12-22 | CVE-2024-11852 | Missing Authorization vulnerability in Bdthemes Element Pack The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. | 4.3 |
2024-12-21 | CVE-2024-12884 | SQL Injection vulnerability in Codezips E-Commerce Site 1.0 A vulnerability was found in Codezips E-Commerce Website 1.0. | 9.8 |
2024-12-21 | CVE-2024-51463 | IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). | 5.4 |
2024-12-21 | CVE-2024-12883 | Cross-site Scripting vulnerability in Anisha JOB Recruitment 1.0 A vulnerability was found in code-projects Job Recruitment 1.0. | 6.1 |
2024-12-21 | CVE-2024-12875 | Path Traversal vulnerability in Awesomemotive Easy Digital Downloads The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. | 4.9 |
2024-12-21 | CVE-2024-10453 | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-12-21 | CVE-2024-11688 | The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. | 6.1 |
2024-12-21 | CVE-2024-11722 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. network high complexity CWE-89 | 5.9 |
2024-12-21 | CVE-2024-12408 | The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. | 6.1 |