Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-02-12 CVE-2025-1197 SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0
A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical.
network
low complexity
fabianros CWE-89
7.5
2025-02-12 CVE-2024-10960 Unrestricted Upload of File with Dangerous Type vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4.
network
low complexity
brizy CWE-434
8.8
2025-02-12 CVE-2024-13480 SQL Injection vulnerability in Eniture LTL Freight Quotes
The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
eniture CWE-89
7.5
2025-02-12 CVE-2024-13532 SQL Injection vulnerability in Eniture Small Package Quotes
The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
eniture CWE-89
7.5
2025-02-12 CVE-2025-1191 SQL Injection vulnerability in Janobe Multi Restaurant Table Reservation System 1.0
A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical.
network
low complexity
janobe CWE-89
8.8
2025-02-12 CVE-2025-1192 SQL Injection vulnerability in Janobe Multi Restaurant Table Reservation System 1.0
A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0.
network
low complexity
janobe CWE-89
8.8
2025-02-12 CVE-2024-12296 Missing Authorization vulnerability in Apusthemes Superio
The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3.
network
low complexity
apusthemes CWE-862
8.8
2025-02-12 CVE-2024-13435 SQL Injection vulnerability in Infoway Ebook Downloader
The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
infoway CWE-89
7.5
2025-02-12 CVE-2024-13473 SQL Injection vulnerability in Eniture LTL Freight Quotes
The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameter in all versions up to, and including, 5.0.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
eniture CWE-89
7.5
2025-02-12 CVE-2024-13475 SQL Injection vulnerability in Eniture Small Package Quotes
The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 4.5.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
eniture CWE-89
7.5