Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13514
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via the 'bsb-slider' shortcode due to insufficient restrictions on which posts can be included. This makes i... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-12046
The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the 'namedical_elementor_template' shortcode due to missing validation on a user controlled key. This ma... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-10239
A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which can cause a stack overflow due to the unchecked fat->fsd.max_fld.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2024-10238
A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack overflow is caused by not checking fld->used_bytes.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2024-10237
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-13607
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled k... Read more
Affected Products : js_help_desk- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-12597
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output esca... Read more
Affected Products : ht_mega- Published: Feb. 04, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-0466
The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.... Read more
Affected Products : sensei_lms- Published: Feb. 04, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-0368
The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unaut... Read more
Affected Products : banner_garden- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13332
The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : transfinanz- Published: Feb. 04, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13331
The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : wp_dream_carousel- Published: Feb. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13330
The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : justrows_free- Published: Feb. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13329
The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : solidres- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13328
The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : giga_messenger- Published: Feb. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13327
The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : musicbox- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13326
The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : ibuildapp- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13325
The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : glossy- Published: Feb. 04, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13115
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSR... Read more
Affected Products : wp_projects_portfolio_with_client_testimonials- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-13114
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users su... Read more
Affected Products : wp_projects_portfolio_with_client_testimonials- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-24982
Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Request Forgery