Latest CVE Feed
-
6.4
CVSS31CVE-2024-13156
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘heading’ parameter in all versions up to, and including, 2.5.35 due to insufficient input sanitization and outp... Read more
Affected Products : html5_video_player- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
4.9
CVSS31CVE-2024-11736
A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
6.5
CVSS31CVE-2024-11734
A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which caus... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
8.5
CVSS31CVE-2024-12365
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with... Read more
Affected Products : w3_total_cache- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
5.3
CVSS31CVE-2024-12008
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive infor... Read more
Affected Products : w3_total_cache- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
5.3
CVSS31CVE-2024-12006
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactiva... Read more
Affected Products : w3_total_cache- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
6.4
CVSS31CVE-2024-13323
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products : wp_booking_calendar- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2024-13348
The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the smartagenda_options_page_html() functi... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
7.2
CVSS30CVE-2025-23082
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
8.8
CVSS31CVE-2024-12398
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escal... Read more
- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23038
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `remuneracao.php` endpoint of the WeGIA application. This vulnerability allows... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23037
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `control.php` endpoint of the WeGIA application. This vulnerability allows att... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23036
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `pre_cadastro_funcionario.php` endpoint of the WeGIA application. This vuln... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23035
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_tipo_quadro_horario.php` endpoint of the WeGIA application. This vu... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23034
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `tags.php` endpoint of the WeGIA application. This vulnerability allows att... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23033
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_situacao.php` endpoint of the WeGIA application. This vulnerability... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23032
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_escala.php` endpoint of the WeGIA application. This vulnerability a... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23031
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_alergia.php` endpoint of the WeGIA application. This vulnerability ... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
0.0
NONECVE-2025-23030
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `cadastro_funcionario.php` endpoint of the WeGIA application. This vulnerab... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
9.9
CVSS31CVE-2025-0070
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can ... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025