911
|
- |
|
-
|
-
|
The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again…
|
-
|
CVE-2024-13112
|
2025-02-1 01:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
912
|
- |
|
-
|
-
|
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this…
|
-
|
CVE-2024-23930
|
2025-02-1 01:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
913
|
- |
|
-
|
-
|
In its default configuration, the affected product transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of conf…
|
-
|
CVE-2025-0683
|
2025-02-1 01:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
914
|
- |
|
-
|
-
|
The affected product sends out remote access requests to a hard-coded IP address, bypassing existing device network settings to do so. This could serve as a backdoor and lead to a malicious actor bei…
|
-
|
CVE-2025-0626
|
2025-02-1 01:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
915
|
6.1 |
MEDIUM
Network
|
wallosapp
|
wallos
|
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.
|
CWE-79
Cross-site Scripting
|
CVE-2024-57386
|
2025-02-1 01:13 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
916
|
5.4 |
MEDIUM
Network
|
theeventscalendar
|
the_events_calendar
|
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12118
|
2025-02-1 01:12 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
917
|
5.4 |
MEDIUM
Network
|
videowhisper
|
broadcast_live_video
|
The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12504
|
2025-02-1 01:05 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
918
|
6.5 |
MEDIUM
Network
|
tainacan
|
tainacan
|
The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient escaping on the user supplied para…
|
CWE-89
SQL Injection
|
CVE-2024-13236
|
2025-02-1 01:03 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
919
|
5.4 |
MEDIUM
Network
|
pluginus
|
meta_data_and_taxonomies_filter
|
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdf_results_by_ajax' shortcode in all versions up to, and including, 1.3…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13340
|
2025-02-1 01:02 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
920
|
5.4 |
MEDIUM
Network
|
cliptakes
|
cliptakes
|
The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email' shortcode in all versions up to, and including, 1.3.4 due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13389
|
2025-02-1 00:59 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|