Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.4

    MEDIUM
    CVE-2024-13387

    The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shortcode in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attribute... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2024-13355

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This make... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Misconfiguration
  • 6.5

    MEDIUM
    CVE-2024-12615

    The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient pr... Read more

    Affected Products : passwords_manager
    • Published: Jan. 16, 2025
    • Modified: Jan. 17, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2024-12614

    The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible ... Read more

    Affected Products : passwords_manager
    • Published: Jan. 16, 2025
    • Modified: Jan. 17, 2025
    • Vuln Type: Authorization
  • 7.5

    HIGH
    CVE-2024-12613

    The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient p... Read more

    Affected Products : passwords_manager
    • Published: Jan. 16, 2025
    • Modified: Jan. 17, 2025
    • Vuln Type: Injection
  • 5.3

    MEDIUM
    CVE-2024-12427

    The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attacke... Read more

    Affected Products : multi_step_form
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Authentication
  • 9.1

    CRITICAL
    CVE-2024-48885

    A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, 6.4.0 t... Read more

    • Published: Jan. 16, 2025
    • Modified: Feb. 03, 2025
    • Vuln Type: Path Traversal
  • 7.8

    HIGH
    CVE-2024-45331

    A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6... Read more

    • Published: Jan. 16, 2025
    • Modified: Feb. 03, 2025
    • Vuln Type: Authorization
  • 6.5

    MEDIUM
    CVE-2024-12226

    In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 a... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Information Disclosure
  • 6.4

    MEDIUM
    CVE-2024-11452

    The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escap... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.3

    MEDIUM
    CVE-2024-10789

    The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for un... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 9.8

    CRITICAL
    CVE-2025-22916

    RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-22913

    RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-22912

    RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-22907

    RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-22906

    RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-22905

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-22904

    RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 8.8

    HIGH
    CVE-2025-0457

    The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.... Read more

    Affected Products : airpass
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-0456

    The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.... Read more

    Affected Products : airpass
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Authentication
Showing 20 of 291269 Results