5.5

CVSS3.1

CVE-2025-21106 -

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.

📅 Published: Feb. 20, 2025, 12:04 p.m. 🔄 Last Modified: July 31, 2025, 5:32 p.m.

9.3

CVSS4.0

CVE-2025-0868 - Remote Code Execution in DocsGPT

A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0.

📅 Published: Feb. 20, 2025, 11:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-1043 - Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contribu…

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and abov…

📅 Published: Feb. 20, 2025, 11:09 a.m. 🔄 Last Modified: April 21, 2026, midnight

6.4

CVSS3.1

CVE-2025-1328 - Typed JS: A typewriter style animation <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘typespeed’ parameter in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 21, 2026, midnight

7.3

CVSS3.1

CVE-2024-13792 - WooCommerce Food - Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode E…

The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

6.4

CVSS3.1

CVE-2024-13802 - Bandsintown Events <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

4.3

CVSS3.1

CVE-2024-13855 - Prime Addons for Elementor <= 2.0.1 - Authenticated (Contributor+) Insecure Direct Object Reference…

The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contribut…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

7.5

CVSS3.1

CVE-2024-13476 - LTL Freight Quotes – GlobalTranz Edition <= 2.3.11 - Unauthenticated SQL Injection

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_dropship' AJAX endpoint in all versions up to, and including, 2.3.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

8.1

CVSS3.1

CVE-2024-13753 - Ultimate Classified Listings <= 1.5 - Cross-Site Request Forgery to Account Takeover

The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's e…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

6.5

CVSS3.1

CVE-2025-0866 - Legoeso PDF Manager <= 1.2.2 - Authenticated (Author+) SQL Injection via checkedVals Parameter

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

📅 Published: Feb. 20, 2025, 9:21 a.m. 🔄 Last Modified: April 22, 2026, 1:30 p.m.
Total resulsts: 346103
Page 6364 of 34,611
« previous page » next page
Filters