5.3

CVSS4.0

CVE-2025-1185 - pihome-shc PiHome ajax.php sql injection

A vulnerability was found in pihome-shc PiHome 2.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?Ajax=GetModal_Sensor_Graph. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the publi…

📅 Published: Feb. 12, 2025, 7:31 a.m. 🔄 Last Modified: Oct. 17, 2025, 3:18 p.m.

5.3

CVSS4.0

CVE-2025-1184 - pihome-shc PiHome ajax.php sql injection

A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?Ajax=GetModal_MQTTEdit. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been di…

📅 Published: Feb. 12, 2025, 7 a.m. 🔄 Last Modified: Oct. 17, 2025, 3:19 p.m.

5.3

CVSS4.0

CVE-2025-1183 - CodeZips Gym Management System more-userprofile.php sql injection

A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/more-userprofile.php. The manipulation of the argument login_id leads to sql injection. The attack can be launched…

📅 Published: Feb. 12, 2025, 6:58 a.m. 🔄 Last Modified: Feb. 25, 2025, 6:32 p.m.

4.3

CVSS3.1

CVE-2024-13601 - Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Authenticated (S…

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key. This makes it …

📅 Published: Feb. 12, 2025, 5:28 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

7.5

CVSS3.1

CVE-2024-13600 - Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Unauthenticated …

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensi…

📅 Published: Feb. 12, 2025, 5:28 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

8.8

CVSS3.1

CVE-2024-13714 - All-Images.ai – IA Image Bank and Custom Image creation <= 1.0.4 - Authenticated (Subscriber+) Arbi…

The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_get_image_by_url' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subs…

📅 Published: Feb. 12, 2025, 5:28 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-13374 - WP Table Manager <= 4.1.3 - Missing Authorization to Authenticated (Subscriber+) Directory Traversa…

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitra…

📅 Published: Feb. 12, 2025, 5:28 a.m. 🔄 Last Modified: April 8, 2026, 4:36 p.m.

8.1

CVSS3.1

CVE-2024-13654 - ZoxPress - The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (…

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'reset_options' function in all versions up to, and including, 2.12.0. This makes it possible for a…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

8.1

CVSS3.1

CVE-2024-13656 - Click Mag - Viral WordPress News Magazine/Blog Theme <= 3.6.0 - Missing Authorization to Authentica…

The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.6.0. This makes …

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

6.4

CVSS3.1

CVE-2024-13658 - NGG Smart Image Search <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.
Total resulsts: 343996
Page 6251 of 34,400
« previous page » next page
Filters