Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-11 CVE-2024-52611 Information Exposure Through an Error Message vulnerability in Solarwinds Platform
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message.
low complexity
solarwinds CWE-209
3.5
2025-02-11 CVE-2024-52612 Unspecified vulnerability in Solarwinds Platform
SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability.
network
low complexity
solarwinds
4.8
2025-02-11 CVE-2025-0180 The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.
network
low complexity
CWE-269
critical
9.8
2025-02-11 CVE-2025-0181 The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.7.
network
low complexity
CWE-288
critical
9.8
2025-02-11 CVE-2025-1179 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.43
A vulnerability was found in GNU Binutils 2.43.
network
high complexity
gnu CWE-119
7.5
2025-02-11 CVE-2024-13543 Cross-site Scripting vulnerability in Amini7 Zarinpal Paid Download
The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
network
low complexity
amini7 CWE-79
6.1
2025-02-11 CVE-2024-13544 Unrestricted Upload of File with Dangerous Type vulnerability in Amini7 Zarinpal Paid Download
The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
network
low complexity
amini7 CWE-434
4.8
2025-02-11 CVE-2024-13570 Cross-site Scripting vulnerability in Unalignedcode Stray Random Quotes
The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
network
low complexity
unalignedcode CWE-79
6.1
2025-02-11 CVE-2025-1176 Heap-based Buffer Overflow vulnerability in GNU Binutils 2.43
A vulnerability was found in GNU Binutils 2.43 and classified as critical.
network
high complexity
gnu CWE-122
5.0
2025-02-11 CVE-2025-1177 Deserialization of Untrusted Data vulnerability in Xunruicms 4.6.3
A vulnerability was found in dayrui XunRuiCMS 4.6.3.
network
low complexity
xunruicms CWE-502
critical
9.8