6.4

CVSS3.1

CVE-2025-0450 - Betheme <= 27.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS

The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackโ€ฆ

๐Ÿ“… Published: Jan. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 3 p.m.

6.5

CVSS3.1

CVE-2024-52973 - Kibana allocation of resources without limits or throttling leads to crash

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summary. This can be carried out by users with read access to the Observability-Logs feature in Kibana.

๐Ÿ“… Published: Jan. 21, 2025, 11:04 a.m. ๐Ÿ”„ Last Modified: Sept. 30, 2025, 9:01 p.m.

6.5

CVSS3.1

CVE-2024-43709 - Elasticsearch allocation of resources without limits or throttling leads to crash

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.

๐Ÿ“… Published: Jan. 21, 2025, 11 a.m. ๐Ÿ”„ Last Modified: Feb. 21, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2024-37284 - Elastic Defend Improper Handling of Alternate Encoding Leads to Crash

Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This leads to an uncaught exception causing Elastic Defend to crash which in turn will prevent it from quarantining the file and/or killing the โ€ฆ

๐Ÿ“… Published: Jan. 21, 2025, 10:56 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-6466 -

NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.

๐Ÿ“… Published: Jan. 21, 2025, 10:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-23184 - Apache CXF: Denial of Service vulnerability with temporary files

A potential denial of service vulnerability is present in versions of Apache CXF beforeย 3.5.10, 3.6.5 and 4.0.6.ย In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).

๐Ÿ“… Published: Jan. 21, 2025, 9:35 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 4:15 p.m.

6.1

CVSS3.1

CVE-2024-13404 - Link Library <= 7.7.2 - Reflected Cross-Site Scripting

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrโ€ฆ

๐Ÿ“… Published: Jan. 21, 2025, 9:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:32 p.m.

5.3

CVSS3.1

CVE-2024-12104 - Visual Website Collaboration, Feedback & Project Management โ€“ Atarim <= 4.0.9 - Missing Authorizatiโ€ฆ

The Visual Website Collaboration, Feedback & Project Management โ€“ Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unaโ€ฆ

๐Ÿ“… Published: Jan. 21, 2025, 9:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:19 p.m.

6.1

CVSS3.1

CVE-2024-12005 - WP-BibTeX <= 3.0.1 - Cross-Site Request Forgery to Stored and Reflected Cross-Site Scripting

The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_option_page() function. This makes it possible for unauthenticated attackers to inject malicious web scriโ€ฆ

๐Ÿ“… Published: Jan. 21, 2025, 9:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2025-0371 - Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widโ€ฆ

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contriโ€ฆ

๐Ÿ“… Published: Jan. 21, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4:30 a.m.
Total resulsts: 346749
Page 6788 of 34,675
ยซ previous page ยป next page
Filters