7.5

CVSS3.1

CVE-2024-13606 - JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Informa…

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored …

📅 Published: Feb. 13, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 5:30 p.m.

6.1

CVSS3.1

CVE-2024-13867 - Listivo - Classified Ads WordPress Theme <= 2.3.67 - Reflected Cross-Site Scripting

The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 2.3.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj…

📅 Published: Feb. 13, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 5 p.m.

7.1

CVSS3.1

CVE-2024-46910 - Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.

📅 Published: Feb. 13, 2025, 8:52 a.m. 🔄 Last Modified: Oct. 17, 2025, 3:50 p.m.

6.4

CVSS3.1

CVE-2024-3303 - Improper Neutralization of Input Used for LLM Prompting in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

📅 Published: Feb. 13, 2025, 8:31 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:32 p.m.

4.3

CVSS3.1

CVE-2024-13639 - Read More & Accordion <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Re…

The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with Subscriber-level access…

📅 Published: Feb. 13, 2025, 8:21 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.

7.3

CVSS3.1

CVE-2024-13345 - Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution

The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauth…

📅 Published: Feb. 13, 2025, 6:58 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

7.3

CVSS3.1

CVE-2024-13346 - Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortco…

📅 Published: Feb. 13, 2025, 6:58 a.m. 🔄 Last Modified: April 8, 2026, 4:40 p.m.

4.3

CVSS3.1

CVE-2025-0661 - DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post Disclosure

The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributo…

📅 Published: Feb. 13, 2025, 6:58 a.m. 🔄 Last Modified: April 8, 2026, 4:40 p.m.

6.9

CVSS4.0

CVE-2025-0814 -

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality of the breaker remains intact during the attack.

📅 Published: Feb. 13, 2025, 6:41 a.m. 🔄 Last Modified: Feb. 13, 2025, 2:54 p.m.

7.1

CVSS4.0

CVE-2025-0815 -

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.

📅 Published: Feb. 13, 2025, 6:39 a.m. 🔄 Last Modified: Feb. 13, 2025, 2:55 p.m.
Total resulsts: 343919
Page 6216 of 34,392
« previous page » next page
Filters