Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-02-10 CVE-2024-13011 The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7.
network
low complexity
CWE-434
critical
9.8
2025-02-08 CVE-2025-0316 The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5.
network
low complexity
CWE-288
critical
9.8
2025-02-07 CVE-2025-24028 Unspecified vulnerability in Joplin Project Joplin
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.
network
low complexity
joplin-project
critical
9.6
2025-02-07 CVE-2025-1104 Authentication Bypass by Spoofing vulnerability in Dlink Dhp-W310Av Firmware 1.04
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical.
network
low complexity
dlink CWE-290
critical
9.8
2025-02-07 CVE-2025-25163 Path Traversal vulnerability in Pluginab Plugin A/B Image Optimizer
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer allows Path Traversal.
network
low complexity
pluginab CWE-22
critical
9.8
2025-02-07 CVE-2025-25167 Missing Authorization vulnerability in Blackandwhitedigital Bookpress 1.2.7
Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
blackandwhitedigital CWE-862
critical
9.8
2025-02-07 CVE-2025-1061 The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16.
network
low complexity
CWE-288
critical
9.8
2025-02-06 CVE-2024-57958 Out-of-bounds Read vulnerability in Huawei Emui and Harmonyos
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-125
critical
9.1
2025-02-06 CVE-2024-57959 Use After Free vulnerability in Huawei Emui and Harmonyos
Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-416
critical
9.8
2025-02-06 CVE-2024-57961 Out-of-bounds Write vulnerability in Huawei Emui and Harmonyos
Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-787
critical
9.8