9.4

CVSS4.0

CVE-2025-22152 - Improper Path Validation Enables Path Traversal in Multiple Components in Atheos

Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These vulnerabilities can be exploited through various attack vecto…

📅 Published: Jan. 10, 2025, 3:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2024-56511 - DataEase has an unauthorized vulnerability

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease.auth.filter.TokenFilter class, ”request.getReques…

📅 Published: Jan. 10, 2025, 3:19 p.m. 🔄 Last Modified: Feb. 20, 2025, 4:26 p.m.

9.8

CVSS3.1

CVE-2024-41787 - IBM Engineering Requirements Management DOORS Next code execution

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

📅 Published: Jan. 10, 2025, 1:18 p.m. 🔄 Last Modified: Aug. 20, 2025, 2:48 a.m.

5.3

CVSS3.1

CVE-2024-13318 - Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page Deletion

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.

📅 Published: Jan. 10, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

6.4

CVSS3.1

CVE-2024-13183 - Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via ti…

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: Jan. 10, 2025, 7:21 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.4

CVSS3.1

CVE-2025-0311 - Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pr…

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Jan. 10, 2025, 6:43 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

6.5

CVSS3.1

CVE-2024-12473 - AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI Wo…

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the 'template_id' parameter of the 'article_builder_generate_data' shortcode in all versions up to, and…

📅 Published: Jan. 10, 2025, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12606 - AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI Wo…

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engine_request_data() function in all versions…

📅 Published: Jan. 10, 2025, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-54848 -

Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.

📅 Published: Jan. 10, 2025, midnight 🔄 Last Modified: Oct. 2, 2025, 4:59 p.m.

4.7

CVSS3.1

CVE-2024-33297 -

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function

📅 Published: Jan. 10, 2025, midnight 🔄 Last Modified: July 3, 2025, 12:40 a.m.
Total resulsts: 345171
Page 6789 of 34,518
« previous page » next page
Filters