681
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allo…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24708
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
682
|
- |
|
-
|
-
|
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue af…
|
CWE-538
File and Directory Information Exposure
|
CVE-2025-24689
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
683
|
- |
|
-
|
-
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locat…
|
CWE-80
Basic XSS
|
CVE-2025-24680
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
684
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Object Injection. This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 4.4.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-24671
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
685
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Small Package Quotes – Worldwide Express Edition allows SQL Injection. This is…
|
CWE-89
SQL Injection
|
CVE-2025-24667
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
686
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Small Package Quotes – Unishippers Edition allows SQL Injection. This issue af…
|
CWE-89
SQL Injection
|
CVE-2025-24665
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
687
|
- |
|
-
|
-
|
Missing Authorization vulnerability in NotFound LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnDash LMS: from n/a through 4.20.0.1.
|
CWE-862
Missing Authorization
|
CVE-2025-24662
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
688
|
- |
|
-
|
-
|
Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhanc…
|
CWE-862
Missing Authorization
|
CVE-2025-24653
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
689
|
- |
|
-
|
-
|
Authentication Bypass by Spoofing vulnerability in BestWebSoft Google Captcha allows Identity Spoofing. This issue affects Google Captcha: from n/a through 1.78.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-24628
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
690
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Music Store allows Reflected XSS. This issue affects Music Store: from n/a through 1.1…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24626
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|