1051
|
9.8 |
CRITICAL
Network
-
|
-
|
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attacke…
|
CWE-22
Path Traversal
|
CVE-2024-13545
|
2025-01-24 18:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1052
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation o…
|
CWE-352
Origin Validation Error
|
CVE-2024-13683
|
2025-01-24 16:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1053
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to ins…
|
CWE-89
SQL Injection
|
CVE-2024-13680
|
2025-01-24 16:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1054
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due to insufficient input saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13659
|
2025-01-24 15:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1055
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site sc…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0314
|
2025-01-24 12:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1056
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have…
|
CWE-1220
Insufficient Granularity of Access Control
|
CVE-2024-11931
|
2025-01-24 12:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1057
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Rejected Reason: This candidate is unused by its CNA.
|
-
|
CVE-2021-30745
|
2025-01-24 11:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1058
|
- |
|
-
|
-
|
Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12c83b38f85c943dee0112e428dc2a43 allows a remote attacker to …
|
-
|
CVE-2024-53379
|
2025-01-24 08:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1059
|
- |
|
-
|
-
|
Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
|
-
|
CVE-2025-0693
|
2025-01-24 07:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1060
|
- |
|
-
|
-
|
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized pac…
|
-
|
CVE-2023-37013
|
2025-01-24 07:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|