Latest CVE Feed
-
0.0
NONECVE-2025-0395
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page siz... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.3
CVSS31CVE-2024-13499
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.5
CVSS31CVE-2024-13496
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.2.1 due to insufficient esca... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.3
CVSS31CVE-2024-13495
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
4.3
CVSS31CVE-2024-13447
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
4.7
CVSS31CVE-2022-23439
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before versio... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.2
CVSS31CVE-2025-0429
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() functi... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.2
CVSS31CVE-2025-0428
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.3
CVSS31CVE-2024-13361
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attac... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
5.4
CVSS31CVE-2024-13360
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-lev... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.1
CVSS31CVE-2024-13319
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated attack... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.1
CVSS31CVE-2024-13406
The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it poss... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
9.8
CVSS31CVE-2024-12857
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unaut... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.4
CVSS31CVE-2024-12117
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output e... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.6
CVSS30CVE-2025-23237
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.5
CVSS30CVE-2025-22450
Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected products, and open specific ports.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
7.2
CVSS30CVE-2025-20617
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can acce... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
4.3
CVSS31CVE-2024-12879
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versions up to, and including, 13.5.5. This makes it possible ... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
8.6
CVSS31CVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the e... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
-
6.4
CVSS31CVE-2024-13590
The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025