Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-11 CVE-2024-13543 Cross-site Scripting vulnerability in Amini7 Zarinpal Paid Download
The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
network
low complexity
amini7 CWE-79
6.1
2025-02-11 CVE-2024-13544 Unrestricted Upload of File with Dangerous Type vulnerability in Amini7 Zarinpal Paid Download
The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
network
low complexity
amini7 CWE-434
4.8
2025-02-11 CVE-2024-13570 Cross-site Scripting vulnerability in Unalignedcode Stray Random Quotes
The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
network
low complexity
unalignedcode CWE-79
6.1
2025-02-11 CVE-2025-1176 Heap-based Buffer Overflow vulnerability in GNU Binutils 2.43
A vulnerability was found in GNU Binutils 2.43 and classified as critical.
network
high complexity
gnu CWE-122
5.0
2025-02-11 CVE-2025-1177 Deserialization of Untrusted Data vulnerability in Xunruicms 4.6.3
A vulnerability was found in dayrui XunRuiCMS 4.6.3.
network
low complexity
xunruicms CWE-502
critical
9.8
2025-02-11 CVE-2025-1173 SQL Injection vulnerability in 1000Projects Bookstore Management System 1.0
A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0.
network
low complexity
1000projects CWE-89
7.2
2025-02-11 CVE-2025-1174 Cross-site Scripting vulnerability in 1000Projects Bookstore Management System 1.0
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic.
network
low complexity
1000projects CWE-79
4.8
2025-02-11 CVE-2025-1171 Cross-site Scripting vulnerability in Fabianros Real Estate Property Management System 1.0
A vulnerability classified as problematic was found in code-projects Real Estate Property Management System 1.0.
network
low complexity
fabianros CWE-79
6.1
2025-02-11 CVE-2025-1172 SQL Injection vulnerability in 1000Projects Bookstore Management System 1.0
A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0.
network
low complexity
1000projects CWE-89
8.8
2025-02-11 CVE-2025-1169 Code Injection vulnerability in Rems Image Compressor Tool 1.0
A vulnerability was found in SourceCodester Image Compressor Tool 1.0.
network
low complexity
rems CWE-94
6.1