2025-01-04 | CVE-2024-41765 | | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. | 6.5 |
2025-01-04 | CVE-2024-41768 | | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state. | 6.5 |
2025-01-04 | CVE-2024-12195 | Wedevs | SQL Injection vulnerability in Wedevs WP Project Manager The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-01-04 | CVE-2025-0201 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. | 6.5 |
2025-01-04 | CVE-2025-0200 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. | 6.5 |
2025-01-03 | CVE-2025-0199 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management System 1.0. | 6.5 |
2025-01-03 | CVE-2025-0198 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. | 6.5 |
2025-01-03 | CVE-2025-0197 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. | 6.5 |
2025-01-03 | CVE-2025-0196 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. | 6.5 |
2025-01-03 | CVE-2025-0195 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. | 6.5 |
2025-01-03 | CVE-2025-0174 | Code Projects | SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0 A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. | 6.5 |
2024-12-31 | CVE-2024-12105 | Progress | Path Traversal vulnerability in Progress Whatsup Gold In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure. | 6.5 |
2024-12-31 | CVE-2024-56216 | Themify | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Themify Builder Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themify Themify Builder allows PHP Local File Inclusion.This issue affects Themify Builder: from n/a through 7.6.3. | 6.5 |
2025-01-04 | CVE-2024-12279 | | The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. | 6.1 |
2025-01-04 | CVE-2024-12221 | | The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. | 6.1 |
2025-01-04 | CVE-2024-11974 | | The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. | 6.1 |
2025-01-04 | CVE-2024-12047 | | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. | 6.1 |
2025-01-04 | CVE-2024-12701 | | The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. | 6.1 |
2025-01-03 | CVE-2025-0175 | Anisha | Cross-site Scripting vulnerability in Anisha Online Shop 1.0 A vulnerability was found in code-projects Online Shop 1.0. | 6.1 |
2025-01-02 | CVE-2024-55541 | Acronis | Cross-site Scripting vulnerability in Acronis Cyber Protect 15/16 Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. | 6.1 |
2024-12-31 | CVE-2024-13082 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability was found in PHPGurukul Land Record System 1.0. | 6.1 |
2024-12-30 | CVE-2024-13033 | Code Projects | Cross-site Scripting vulnerability in Code-Projects Chat System 1.0 A vulnerability, which was classified as problematic, has been found in code-projects Chat System 1.0. | 6.1 |
2025-01-04 | CVE-2024-41763 | | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 |
2025-01-05 | CVE-2025-0222 | I0Bit | NULL Pointer Dereference vulnerability in I0Bit Protected Folder A vulnerability was found in IObit Protected Folder up to 13.6.0.5 and classified as problematic. | 5.5 |
2025-01-05 | CVE-2025-0223 | I0Bit | NULL Pointer Dereference vulnerability in I0Bit Protected Folder A vulnerability was found in IObit Protected Folder up to 13.6.0.5. | 5.5 |
2025-01-05 | CVE-2025-0221 | I0Bit | NULL Pointer Dereference vulnerability in I0Bit Protected Folder A vulnerability has been found in IOBit Protected Folder up to 1.3.0 and classified as problematic. | 5.5 |
2025-01-02 | CVE-2022-49035 | Linux | Allocation of Resources Without Limits or Throttling vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware will have limited this to 16, but just in case it hasn't, check for this corner case. | 5.5 |
2025-01-05 | CVE-2024-13141 | Osuuu | Cross-site Scripting vulnerability in Osuuu Lightpicture 1.2.0/1.2.1/1.2.2 A vulnerability classified as problematic was found in osuuu LightPicture up to 1.2.2. | 5.4 |
2025-01-05 | CVE-2024-13140 | Emlog | Cross-site Scripting vulnerability in Emlog A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.3. | 5.4 |
2025-01-05 | CVE-2024-13137 | Wangl1989 | Cross-site Scripting vulnerability in Wangl1989 Mysiteforme 1.0 A vulnerability was found in wangl1989 mysiteforme 1.0. | 5.4 |
2025-01-05 | CVE-2024-13135 | Emlog | Cross-site Scripting vulnerability in Emlog 2.4.3 A vulnerability has been found in Emlog Pro 2.4.3 and classified as problematic. | 5.4 |
2025-01-05 | CVE-2024-13132 | Emlog | Cross-site Scripting vulnerability in Emlog A vulnerability classified as problematic was found in Emlog Pro up to 2.4.3. | 5.4 |
2025-01-04 | CVE-2024-12475 | Wpexperts | Cross-site Scripting vulnerability in Wpexperts WP Multi Store Locator 2.4 The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. | 5.4 |
2025-01-04 | CVE-2024-11930 | Taskbuilder | Cross-site Scripting vulnerability in Taskbuilder The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-01-04 | CVE-2024-12545 | | The Scratch & Win – Giveaways and Contests. | 5.4 |
2025-01-03 | CVE-2024-55896 | | IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. | 5.4 |
2025-01-03 | CVE-2024-56411 | Phpoffice | Cross-site Scripting vulnerability in PHPoffice PHPspreadsheet PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. | 5.4 |
2025-01-03 | CVE-2024-56412 | Phpoffice | Cross-site Scripting vulnerability in PHPoffice PHPspreadsheet PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. | 5.4 |
2025-01-02 | CVE-2023-23672 | Givewp | Missing Authorization vulnerability in Givewp Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1. | 5.4 |
2025-01-02 | CVE-2024-56252 | Themelooks | Cross-site Scripting vulnerability in Themelooks Enter Addons Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.9. | 5.4 |
2025-01-02 | CVE-2024-56254 | Moveaddons | Cross-site Scripting vulnerability in Moveaddons Move Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.6. | 5.4 |
2024-12-31 | CVE-2024-56063 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.0.7. | 5.4 |
2024-12-31 | CVE-2024-13083 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. | 5.4 |
2024-12-31 | CVE-2024-13081 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability was found in PHPGurukul Land Record System 1.0. | 5.4 |
2024-12-31 | CVE-2024-13080 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability was found in PHPGurukul Land Record System 1.0. | 5.4 |
2024-12-31 | CVE-2024-13077 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. | 5.4 |
2024-12-31 | CVE-2024-13075 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. | 5.4 |
2024-12-31 | CVE-2024-13076 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Land Record System 1.0 A vulnerability, which was classified as problematic, has been found in PHPGurukul Land Record System 1.0. | 5.4 |
2024-12-31 | CVE-2023-6602 | | A flaw was found in FFmpeg's TTY Demuxer. | 5.3 |
2024-12-30 | CVE-2024-13032 | Antabot | Server-Side Request Forgery (SSRF) vulnerability in Antabot White-Jotter A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. | 4.9 |
2025-01-05 | CVE-2024-13142 | Zerowdd | Cross-site Scripting vulnerability in Zerowdd Studentmanager 1.0 A vulnerability was found in ZeroWdd studentmanager 1.0. | 4.8 |
2025-01-05 | CVE-2025-0228 | Code Projects | Cross-site Scripting vulnerability in Code-Projects Local Storage Todo APP 1.0 A vulnerability has been found in code-projects Local Storage Todo App 1.0 and classified as problematic. | 4.8 |
2024-12-30 | CVE-2024-13031 | Antabot | Cross-site Scripting vulnerability in Antabot White-Jotter A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. | 4.8 |
2025-01-03 | CVE-2024-12237 | | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justified_gallery_callback function. | 4.3 |
2025-01-03 | CVE-2024-55897 | | IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. | 4.3 |
2025-01-03 | CVE-2024-5591 | | IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | 4.3 |
2025-01-03 | CVE-2024-12132 | Wpjobportal | Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. | 4.3 |
2025-01-02 | CVE-2023-45272 | 10Web | Missing Authorization vulnerability in 10Web MAP Builder for Google Maps Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.73. | 4.3 |
2025-01-02 | CVE-2023-47807 | 10Web | Missing Authorization vulnerability in 10Web 10Webanalytics Missing Authorization vulnerability in 10Web 10WebAnalytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through 1.2.12. | 4.3 |
2025-01-02 | CVE-2023-45101 | Cusrev | Missing Authorization vulnerability in Cusrev Customer Reviews for Woocommerce Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0. | 4.3 |
2025-01-02 | CVE-2023-45765 | Wedevs | Missing Authorization vulnerability in Wedevs WP ERP Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through 1.12.6. | 4.3 |
2025-01-03 | CVE-2024-41780 | | IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry. | 4.2 |