9

CVSS3.1

CVE-2025-2311 - Authentication Bypass in Sechard Information Technologies' SecHard

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitori…

📅 Published: March 20, 2025, 11:55 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS4.0

CVE-2025-27888 - Apache Druid: Server-Side Request Forgery and Cross-Site Scripting

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When us…

📅 Published: March 20, 2025, 11:29 a.m. 🔄 Last Modified: July 14, 2025, 12:58 p.m.

4.9

CVSS3.1

CVE-2024-13920 - Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Admini…

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents…

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.

7.2

CVSS3.1

CVE-2024-13921 - Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection …

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level …

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.

6.4

CVSS3.1

CVE-2025-1802 - HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site S…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This…

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 21, 2026, 10 p.m.

7.5

CVSS3.1

CVE-2025-2539 - File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read…

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 21, 2026, 10 p.m.

7.5

CVSS3.1

CVE-2024-13558 - NP Quote Request for WooCommerce <= 1.9.179 - Insecure Direct Object Reference to Unauthenticated S…

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests.

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

2.7

CVSS3.1

CVE-2024-13922 - Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Admini…

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator…

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 4:51 p.m.

7.6

CVSS3.1

CVE-2024-13923 - Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side R…

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web …

📅 Published: March 20, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

7.1

CVSS3.1

CVE-2024-10956 - Cross-Site WebSocket Hijacking in binary-husky/gpt_academic

GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized actions such as deleting …

📅 Published: March 20, 2025, 10:11 a.m. 🔄 Last Modified: July 15, 2025, 11:15 a.m.
Total resulsts: 349182
Page 6264 of 34,919
« previous page » next page
Filters