6.4

CVSS3.1

CVE-2024-13156 - HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.35 - Authenticated (Contributor+) DOM…

The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘heading’ parameter in all versions up to, and including, 2.5.35 due to insufficient input sanitization and output escaping. This makes it possible for auth…

📅 Published: Jan. 14, 2025, 8:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-0394 - Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Functi…

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for a…

📅 Published: Jan. 14, 2025, 8:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-0393 - Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Si…

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attacker…

📅 Published: Jan. 14, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

5.3

CVSS3.1

CVE-2024-12008 - W3 Total Cache <= 2.8.1 Information Exposure via Log Files

The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example,…

📅 Published: Jan. 14, 2025, 7:05 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

5.3

CVSS3.1

CVE-2024-12006 - W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions…

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deacti…

📅 Published: Jan. 14, 2025, 7:05 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

8.5

CVSS3.1

CVE-2024-12365 - W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request …

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtai…

📅 Published: Jan. 14, 2025, 7:05 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.4

CVSS3.1

CVE-2024-13323 - Booking Calendar <= 10.9.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via…

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Jan. 14, 2025, 5:24 a.m. 🔄 Last Modified: April 8, 2026, 4:46 p.m.

0.0

CVE-2024-13348 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22506 Reason: This candidate is a reservation duplicate of CVE-2025-22506. Notes: All CVE users should reference CVE-2025-22506 instead of this candidate. All references and descriptions in this candidate have been removed to preve…

📅 Published: Jan. 14, 2025, 3:23 a.m. 🔄 Last Modified: Jan. 30, 2025, 3:15 p.m.

7.2

CVSS3.0

CVE-2025-23082 -

Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

📅 Published: Jan. 14, 2025, 1:46 a.m. 🔄 Last Modified: Nov. 18, 2025, 1:19 p.m.

8.8

CVSS3.1

CVE-2024-12398 -

An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administr…

📅 Published: Jan. 14, 2025, 1:39 a.m. 🔄 Last Modified: Jan. 21, 2025, 9:12 p.m.
Total resulsts: 345363
Page 6771 of 34,537
« previous page » next page
Filters