5.1

CVSS4.0

CVE-2024-12429 -

An attacker who successfully exploited these vulnerabilities could grant read access to files.ย A vulnerability exists in the AC500 V3 version mentioned. Aย successfully authenticated attacker can use this vulnerability to read system wide files and configuration All AC500 V3 products (PM5xxx) witโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-22354 - WordPress Digi Store theme <= 1.1.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Themes Digi Store allows DOM-Based XSS.This issue affects Digi Store: from n/a through 1.1.4.

๐Ÿ“… Published: Jan. 7, 2025, 4:52 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:10 p.m.

6.5

CVSS3.1

CVE-2025-22365 - WordPress EMC2 Alert Boxes Plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 Alert Boxes allows Stored XSS.This issue affects EMC2 Alert Boxes: from n/a through 1.3.

๐Ÿ“… Published: Jan. 7, 2025, 4:51 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:11 p.m.

6.5

CVSS3.1

CVE-2025-22500 - WordPress Alpha Price Table For Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Ali Alpha Price Table For Elementor alpha-price-table-for-elementor allows DOM-Based XSS.This issue affects Alpha Price Table For Elementor: from n/a through <= 1.2.0.

๐Ÿ“… Published: Jan. 7, 2025, 4:50 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.6

CVSS3.1

CVE-2025-22350 - WordPress Indeed Ultimate Learning Pro plugin <= 3.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: from n/a through 3.9.

๐Ÿ“… Published: Jan. 7, 2025, 4:48 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:10 p.m.

6.4

CVSS3.1

CVE-2025-22621 - Privilege escalation for users who hold the โ€œsplunk_app_soarโ€œ role in the Splunk App for SOAR

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:48 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-56270 - WordPress WP SecureSubmit plugin <= 1.5.20 - Sensitive Data Exposure vulnerability

Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data.This issue affects WP SecureSubmit: from n/a through <= 1.5.20.

๐Ÿ“… Published: Jan. 7, 2025, 4:47 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

4.3

CVSS3.1

CVE-2024-56272 - WordPress Hide Category by User Role for WooCommerce plugin <= 2.1.1 - Broken Access Control vulnerโ€ฆ

Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1.

๐Ÿ“… Published: Jan. 7, 2025, 4:46 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

5.3

CVSS4.0

CVE-2025-0299 - code-projects Online Book Shop search_result.php sql injection

A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to theโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: April 7, 2025, 6:42 p.m.

7.3

CVSS4.0

CVE-2024-12430 -

An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject arbitrary commands into aโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:28 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7236 of 34,919
ยซ previous page ยป next page
Filters