611
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on a function. This makes…
|
CWE-352
Origin Validation Error
|
CVE-2024-13444
|
2025-01-21 20:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
612
|
5.3 |
MEDIUM
Network
-
|
-
|
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, …
|
CWE-89
SQL Injection
|
CVE-2024-13230
|
2025-01-21 20:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
613
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 1.2 due to insufficient input saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11226
|
2025-01-21 20:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
614
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ovl: support encoding fid from inode with no alias
Dmitry Safonov reported that a WARN_ON() assertion can be trigered by
userspac…
|
-
|
CVE-2025-21654
|
2025-01-21 20:15 |
2025-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
615
|
- |
|
-
|
-
|
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-23184
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
616
|
- |
|
-
|
-
|
NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.
|
-
|
CVE-2024-6466
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
617
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13404
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
618
|
5.3 |
MEDIUM
Network
-
|
-
|
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and w…
|
CWE-862
Missing Authorization
|
CVE-2024-12104
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
619
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_optio…
|
CWE-352
Origin Validation Error
|
CVE-2024-12005
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
620
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output e…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0371
|
2025-01-21 18:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|