Latest CVE Feed
-
3.5
LOWCVE-2025-0692
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili... Read more
Affected Products : simple_video_management_system- Published: Feb. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13125
The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : everest_forms- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13121
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13120
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13119
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12586
The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : chalet-montagne.com_tools- Published: Feb. 13, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2024-10083
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.... Read more
Affected Products :- Published: Feb. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-0837
The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti... Read more
Affected Products : puzzles- Published: Feb. 13, 2025
- Modified: Feb. 24, 2025
-
9.8
CRITICALCVE-2024-13770
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it p... Read more
Affected Products : puzzles- Published: Feb. 13, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-13229
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it poss... Read more
Affected Products : seo- Published: Feb. 13, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-13227
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output esca... Read more
Affected Products : seo- Published: Feb. 13, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-10763
The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitr... Read more
Affected Products : campress- Published: Feb. 13, 2025
- Modified: Feb. 24, 2025
-
5.3
MEDIUMCVE-2025-1198
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming r... Read more
Affected Products : gitlab- Published: Feb. 13, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0896
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.... Read more
Affected Products : orthanc- Published: Feb. 13, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2024-13644
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attri... Read more
Affected Products : dethemekit_for_elementor- Published: Feb. 13, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-25286
Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. T... Read more
Affected Products :- Published: Feb. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Misconfiguration
-
6.6
MEDIUMCVE-2024-8266
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.... Read more
Affected Products : gitlab- Published: Feb. 13, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2024-7102
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.... Read more
Affected Products : gitlab- Published: Feb. 13, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-51376
Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action?path= component.... Read more
Affected Products :- Published: Feb. 12, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2024-34521
A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the file permissions of the privileged system user running the ap... Read more
Affected Products :- Published: Feb. 12, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Path Traversal