641
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9…
|
CWE-862
Missing Authorization
|
CVE-2024-11134
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
642
|
5.3 |
MEDIUM
Network
-
|
-
|
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9…
|
CWE-862
Missing Authorization
|
CVE-2024-11133
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
643
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11132
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
644
|
- |
|
-
|
-
|
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
|
-
|
CVE-2024-12510
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
645
|
- |
|
-
|
-
|
A heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause Denial of Service (DoS) via escaping special XML characters.
|
-
|
CVE-2024-53319
|
2025-02-4 05:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
646
|
- |
|
-
|
-
|
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into …
|
-
|
CVE-2024-57665
|
2025-02-4 05:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
647
|
5.3 |
MEDIUM
Network
apple
|
macos
|
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.
|
NVD-CWE-noinfo
|
CVE-2025-24140
|
2025-02-4 05:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
648
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
afs: Fix merge preference rule failure condition
syzbot reported a lock held when returning to userspace[1]. This is
because if …
|
CWE-667
Improper Locking
|
CVE-2025-21672
|
2025-02-4 05:04 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
649
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix bpf_sk_select_reuseport() memory leak
As pointed out in the original comment, lookup in sockmap can return a TCP
ESTABLI…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2025-21683
|
2025-02-4 05:01 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
650
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
iomap: avoid avoid truncating 64-bit offset to 32 bits
on 32-bit kernels, iomap_write_delalloc_scan() was inadvertently using a
3…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-21667
|
2025-02-4 05:00 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|