1261
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 d…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13422
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1262
|
- |
|
-
|
-
|
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 allows a highly privileged attacker to cause denial of service via configuration change.
|
-
|
CVE-2025-0648
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1263
|
- |
|
-
|
-
|
Denial of service condition in M-Files Server in versions before
25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.
|
-
|
CVE-2025-0635
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1264
|
- |
|
-
|
-
|
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
|
-
|
CVE-2025-0619
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1265
|
- |
|
-
|
-
|
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in Kibana UI. This can be carried out by users with r…
|
-
|
CVE-2024-43708
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1266
|
7.5 |
HIGH
Network
-
|
-
|
The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and including, 2.1.2 due to insufficient escaping on the us…
|
CWE-89
SQL Injection
|
CVE-2024-13234
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1267
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12043
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1268
|
7.5 |
HIGH
Network
|
-
|
-
|
The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. This makes it possible for authentica…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-13593
|
2025-01-23 19:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1269
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The i…
|
CWE-352
Origin Validation Error
|
CVE-2024-13511
|
2025-01-23 19:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1270
|
- |
|
-
|
-
|
A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion.
Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS S…
|
-
|
CVE-2024-12957
|
2025-01-23 19:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|