Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-03-30 CVE-2025-1219 Unspecified vulnerability in PHP
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect.
network
low complexity
php
5.3
2025-03-29 CVE-2024-11180 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2025-03-29 CVE-2024-13557 The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6.
network
low complexity
CWE-94
6.5
2025-03-29 CVE-2025-2840 The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script.
network
low complexity
CWE-200
5.3
2025-03-29 CVE-2024-43186 IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
network
high complexity
CWE-256
5.3
2025-03-29 CVE-2024-51477 IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
network
low complexity
CWE-203
4.3
2025-03-29 CVE-2024-7577 IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.
network
high complexity
CWE-532
4.4
2025-03-28 CVE-2024-6875 A vulnerability was found in the Infinispan component in Red Hat Data Grid.
network
low complexity
CWE-401
6.5
2025-03-28 CVE-2025-2924 Heap-based Buffer Overflow vulnerability in Hdfgroup Hdf5
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6.
local
low complexity
hdfgroup CWE-122
5.5
2025-03-28 CVE-2025-2925 Double Free vulnerability in Hdfgroup Hdf5
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic.
local
low complexity
hdfgroup CWE-415
5.5