2691
|
5.3 |
MEDIUM
Network
-
|
-
|
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and w…
|
CWE-862
Missing Authorization
|
CVE-2024-12104
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2692
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_optio…
|
CWE-352
Origin Validation Error
|
CVE-2024-12005
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2693
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output e…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0371
|
2025-01-21 18:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2694
|
8.8 |
HIGH
Network
|
-
|
-
|
The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace'…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10936
|
2025-01-21 18:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2695
|
5.3 |
MEDIUM
Network
-
|
-
|
The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly acce…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-13536
|
2025-01-21 14:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2696
|
- |
|
-
|
-
|
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.
|
-
|
CVE-2025-0356
|
2025-01-21 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2697
|
- |
|
-
|
-
|
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.…
|
-
|
CVE-2025-0355
|
2025-01-21 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2698
|
- |
|
-
|
-
|
Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP…
|
-
|
CVE-2025-0354
|
2025-01-21 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2699
|
- |
|
-
|
-
|
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in ba…
|
-
|
CVE-2025-24014
|
2025-01-21 12:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2700
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-45091
|
2025-01-21 10:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|