9.4

CVSS4.0

CVE-2024-13871 - Unauthenticated Command Injection in Bitdefender BOX v1

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code exec…

📅 Published: March 12, 2025, 11:48 a.m. 🔄 Last Modified: July 30, 2025, 12:40 a.m.

9.4

CVSS4.0

CVE-2024-13872 - Bitdefender Box Insecure Update Mechanism Vulnerability in libboxhermes.so

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and netw…

📅 Published: March 12, 2025, 11:47 a.m. 🔄 Last Modified: July 30, 2025, 12:39 a.m.

6.4

CVSS3.1

CVE-2025-1527 - ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (forme…

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash Sale Countdown module in all versions up to, and including, 3.1.0 due to insuffi…

📅 Published: March 12, 2025, 11:13 a.m. 🔄 Last Modified: April 8, 2026, 5:25 p.m.

5.3

CVSS3.1

CVE-2025-2239 - Absolute Path Disclosure Vulnerability in Hillstone Next Generation FireWall

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.

📅 Published: March 12, 2025, 9:53 a.m. 🔄 Last Modified: March 12, 2025, 2:18 p.m.

9.8

CVSS3.1

CVE-2024-13446 - Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover

The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. passw…

📅 Published: March 12, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 5:01 p.m.

4.3

CVSS3.1

CVE-2024-13430 - Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Pri…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included. This makes it poss…

📅 Published: March 12, 2025, 8:21 a.m. 🔄 Last Modified: April 8, 2026, 4:40 p.m.

6.4

CVSS3.1

CVE-2024-12589 - Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contribut…

The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the countdown timer in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for …

📅 Published: March 12, 2025, 7 a.m. 🔄 Last Modified: April 8, 2026, 5:15 p.m.

5.5

CVSS3.1

CVE-2024-13838 - Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authe…

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authentic…

📅 Published: March 12, 2025, 7 a.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.

5.3

CVSS3.1

CVE-2024-13498 - NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitiv…

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes …

📅 Published: March 12, 2025, 5:22 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

3.7

CVSS3.1

CVE-2025-24912 - hostapd: RADIUS Packet Processing Flaw in hostapd

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

📅 Published: March 12, 2025, 4:43 a.m. 🔄 Last Modified: Oct. 24, 2025, 6:40 p.m.
Total resulsts: 343935
Page 5835 of 34,394
« previous page » next page
Filters