Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-30 CVE-2025-0571 Out-of-bounds Write vulnerability in Santesoft Sante Pacs Server
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability.
network
low complexity
santesoft CWE-787
6.5
2025-01-30 CVE-2025-0572 Path Traversal vulnerability in Santesoft Sante Pacs Server
Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability.
network
low complexity
santesoft CWE-22
4.3
2025-01-30 CVE-2025-0573 Path Traversal vulnerability in Santesoft Sante Pacs Server
Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability.
network
low complexity
santesoft CWE-22
5.3
2025-01-30 CVE-2025-0880 A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical.
network
low complexity
CWE-74
6.3
2025-01-30 CVE-2025-0882 A vulnerability was found in code-projects Chat System up to 1.0.
network
low complexity
CWE-74
6.3
2025-01-30 CVE-2024-10847 Cross-site Scripting vulnerability in Sellerthemes Storely
The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 16.6 due to insufficient input sanitization and output escaping.
network
low complexity
sellerthemes CWE-79
5.4
2025-01-30 CVE-2024-11583 Missing Authorization vulnerability in Visualmodo Borderless
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9.
network
low complexity
visualmodo CWE-862
4.3
2025-01-30 CVE-2024-12102 Unspecified vulnerability in Seventhqueen Typer Core
The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included.
network
low complexity
seventhqueen
4.3
2025-01-30 CVE-2024-12177 Cross-site Scripting vulnerability in Wpmessiah AI Image ALT Text Generator for WP
The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.
network
low complexity
wpmessiah CWE-79
6.1
2025-01-30 CVE-2024-12299 Cross-site Scripting vulnerability in Bowo System Dashboard 2.8.7
The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping.
network
low complexity
bowo CWE-79
6.1