Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-14 CVE-2025-23857 Cross-site Scripting vulnerability in Smartdatasoft Essential WP Real Estate
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Essential WP Real Estate allows Reflected XSS.
network
low complexity
smartdatasoft CWE-79
6.1
2025-02-14 CVE-2024-13791 Path Traversal vulnerability in Bitapps BIT Assist 1.1.9
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function.
network
low complexity
bitapps CWE-22
4.9
2025-02-14 CVE-2025-0821 SQL Injection vulnerability in Bitapps BIT Assist 1.1.9
Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
bitapps CWE-89
6.5
2025-02-14 CVE-2024-13735 Cross-site Scripting vulnerability in Hurrytimer
The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping of a campaign name.
network
low complexity
hurrytimer CWE-79
5.4
2025-02-14 CVE-2024-9601 Cross-site Scripting vulnerability in Themeum Qubely
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping.
network
low complexity
themeum CWE-79
5.4
2025-02-14 CVE-2024-13641 Unspecified vulnerability in Wpswings Return Refund and Exchange for Woocommerce
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory.
network
low complexity
wpswings
7.5
2025-02-14 CVE-2024-13692 Authorization Bypass Through User-Controlled Key vulnerability in Wpswings Return Refund and Exchange for Woocommerce
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key.
network
low complexity
wpswings CWE-639
5.4
2025-02-14 CVE-2024-55904 IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
network
low complexity
CWE-78
7.2
2025-02-13 CVE-2025-22480 Link Following vulnerability in Dell Supportassist 3.2.0.90
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability.
local
low complexity
dell CWE-59
7.8
2025-02-13 CVE-2025-25352 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.
network
low complexity
phpgurukul CWE-89
7.2