Latest CVE Feed
-
8.8
HIGHCVE-2024-13361
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attac... Read more
Affected Products : aipower- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-13360
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-lev... Read more
Affected Products : aipower- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-13319
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated attack... Read more
- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13406
The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it poss... Read more
Affected Products : xml_for_google_merchant_center- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-12857
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unaut... Read more
Affected Products : adforest- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2024-12117
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output e... Read more
Affected Products : stackable- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.6
MEDIUMCVE-2025-23237
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-22450
Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected products, and open specific ports.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-20617
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If an attacker logs in to the affected product with an administrative account and manipulates requests ... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-12879
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versions up to, and including, 13.5.5. This makes it possible ... Read more
- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the e... Read more
Affected Products : enterprise_linux openshift_container_platform international_components_for_unicode- Published: Jan. 22, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Race Condition
-
6.4
MEDIUMCVE-2024-13590
The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products : ketchup_shortcodes- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13584
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up to, and including, 1.5.19 due to insufficient input sanit... Read more
Affected Products : picture_gallery- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13426
The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes ... Read more
Affected Products : wp-polls- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-23083
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be g... Read more
Affected Products : node.js- Published: Jan. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
3.1
LOWCVE-2025-0625
A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads to improper control of resource identifiers. It is possib... Read more
Affected Products : school_management_software- Published: Jan. 22, 2025
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2024-13091
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible for unauthentica... Read more
Affected Products : wpot- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2023-37039
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allow network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet miss... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2024-49749
In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-49748
In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploita... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption