0.0

CVE-2025-0646 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: Jan. 22, 2025, 2:01 p.m. 🔄 Last Modified: July 9, 2025, 10:15 p.m.

6.2

CVSS3.1

CVE-2025-0395 - glibc: buffer overflow in the GNU C Library's assert()

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

📅 Published: Jan. 22, 2025, 1:11 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-13496 - GamiPress <= 7.3.1 - Unauthenticated SQL Injection via orderby Parameter

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack…

📅 Published: Jan. 22, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

4.3

CVSS3.1

CVE-2024-13447 - WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retriev…

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and…

📅 Published: Jan. 22, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

7.3

CVSS3.1

CVE-2024-13499 - GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Fun…

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This is due to the software allowing users to ex…

📅 Published: Jan. 22, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

7.3

CVSS3.1

CVE-2024-13495 - GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Func…

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1. This is due to the software allowing users …

📅 Published: Jan. 22, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 4:53 p.m.

4.1

CVSS3.1

CVE-2022-23439 -

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver

📅 Published: Jan. 22, 2025, 9:10 a.m. 🔄 Last Modified: Jan. 14, 2026, 2:16 p.m.

7.2

CVSS3.1

CVE-2025-0429 - AI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_expor…

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated attackers, wit…

📅 Published: Jan. 22, 2025, 7:29 a.m. 🔄 Last Modified: April 21, 2026, 10:30 p.m.

6.1

CVSS3.1

CVE-2024-13319 - Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

📅 Published: Jan. 22, 2025, 7:29 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

7.2

CVSS3.1

CVE-2025-0428 - AI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_expor…

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated attackers, with a…

📅 Published: Jan. 22, 2025, 7:29 a.m. 🔄 Last Modified: April 22, 2026, 1:45 p.m.
Total resulsts: 349182
Page 7006 of 34,919
« previous page » next page
Filters