7.2

CVSS4.0

CVE-2025-1058 -

CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.

πŸ“… Published: Feb. 13, 2025, 5:45 a.m. πŸ”„ Last Modified: Feb. 13, 2025, 4:30 p.m.

6.8

CVSS4.0

CVE-2024-10083 -

CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.

πŸ“… Published: Feb. 13, 2025, 5:40 a.m. πŸ”„ Last Modified: Feb. 13, 2025, 2:29 p.m.

9.8

CVSS3.1

CVE-2024-10763 - Campress <= 1.35 - Unauthenticated Local File Inclusion

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execut…

πŸ“… Published: Feb. 13, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

8.1

CVSS3.1

CVE-2024-13770 - Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Obje…

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for unauthenticated attackers to inj…

πŸ“… Published: Feb. 13, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:09 p.m.

6.4

CVSS3.1

CVE-2025-0837 - Puzzles <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and a…

πŸ“… Published: Feb. 13, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 6:23 p.m.

4.3

CVSS3.1

CVE-2024-13229 - Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema D…

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contr…

πŸ“… Published: Feb. 13, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:54 p.m.

6.4

CVSS3.1

CVE-2024-13227 - Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Sto…

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

πŸ“… Published: Feb. 13, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2024-13644 - DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via De…

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

πŸ“… Published: Feb. 13, 2025, 1:44 a.m. πŸ”„ Last Modified: April 8, 2026, 4:54 p.m.

9.2

CVSS4.0

CVE-2025-0896 - Orthanc Server Missing Authentication for Critical Function

Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.

πŸ“… Published: Feb. 13, 2025, 1:02 a.m. πŸ”„ Last Modified: July 30, 2025, 6:11 p.m.

4.2

CVSS3.1

CVE-2025-1198 - Insufficient Session Expiration in GitLab

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

πŸ“… Published: Feb. 13, 2025, 12:55 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 6:50 p.m.
Total resulsts: 343825
Page 6209 of 34,383
Β« previous page Β» next page
Filters