6.5

CVSS3.1

CVE-2025-1414 - Memory safety bugs fixed in Firefox 135.0.1

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135.0.1.

πŸ“… Published: Feb. 18, 2025, 1:39 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

5.7

CVSS3.1

CVE-2025-1035 - Path Traversal in Komtera Technolgies' KLog Server

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

πŸ“… Published: Feb. 18, 2025, 11:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-13783 - FormCraft <= 3.9.11 - Missing Authorization to Plugin Data Export in formcraft-main.php

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all plugin data…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:33 p.m.

6.5

CVSS3.1

CVE-2024-13691 - Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary …

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

5.4

CVSS3.1

CVE-2024-13667 - Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via mle-description

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access …

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2025-0817 - FormCraft - Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting …

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 22, 2026, 3 p.m.

7.5

CVSS3.1

CVE-2024-13681 - Uncode <= 2.9.1.6 - Unauthenticated Arbitrary File Read in uncode_admin_get_oembed

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

0.0

CVE-2024-13636 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-24926. Reason: This candidate is a reservation duplicate of CVE-2024-24926. Notes: All CVE users should reference CVE-2024-24926 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: Feb. 24, 2025, 10:15 p.m.

7.2

CVSS3.1

CVE-2025-0521 - Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 22, 2026, 1:30 p.m.

7.3

CVSS3.1

CVE-2024-13797 - PressMart - Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shor…

The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sho…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 4:42 p.m.
Total resulsts: 348624
Page 6644 of 34,863
Β« previous page Β» next page
Filters