121
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13612
|
2025-02-1 22:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
122
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file deldoc.php. The manipulation of the ar…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0943
|
2025-02-1 20:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
123
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 v…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13429
|
2025-02-1 17:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
124
|
5.3 |
MEDIUM
Network
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 v…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13428
|
2025-02-1 17:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
125
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 v…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13425
|
2025-02-1 17:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
126
|
5.3 |
MEDIUM
Network
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 v…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13372
|
2025-02-1 17:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
127
|
5.3 |
MEDIUM
Network
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the…
New
|
CWE-862
Missing Authorization
|
CVE-2024-13371
|
2025-02-1 17:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
128
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including,…
New
|
CWE-862
Missing Authorization
|
CVE-2024-12825
|
2025-02-1 17:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
129
|
- |
|
-
|
-
|
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.
New
|
-
|
CVE-2025-23091
|
2025-02-1 16:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
130
|
6.3 |
MEDIUM
Network
|
-
|
-
|
The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This ma…
New
|
CWE-862
Missing Authorization
|
CVE-2025-0939
|
2025-02-1 16:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|