7.3

CVSS3.1

CVE-2024-13487 - CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via…

The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution via the get_products_price() function in all versions up to, and including, 2.2.5. This is due to the softwar…

📅 Published: Feb. 6, 2025, 6:53 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-0522 - LikeBot – Decentralized like-system <= 0.85 - Admin+ Stored XSS via CSRF

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

📅 Published: Feb. 6, 2025, 6 a.m. 🔄 Last Modified: May 23, 2025, 4:49 p.m.

9.3

CVSS4.0

CVE-2024-51547 - Credentials Disclosure - keys

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

📅 Published: Feb. 6, 2025, 4:12 a.m. 🔄 Last Modified: May 23, 2025, 10:15 a.m.

6.5

CVSS3.1

CVE-2025-0799 - IBM App Connect Enterprise Arbitrary File Write

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.

📅 Published: Feb. 6, 2025, 12:24 a.m. 🔄 Last Modified: Aug. 12, 2025, 6:46 p.m.

9.1

CVSS3.1

CVE-2024-51450 - IBM Security Verify Directory Command Execution

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

📅 Published: Feb. 6, 2025, 12:15 a.m. 🔄 Last Modified: Aug. 8, 2025, 4:59 p.m.

7.8

CVSS3.1

CVE-2024-49814 - IBM Security Verify Access Appliance Privilege Escalation

IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.

📅 Published: Feb. 6, 2025, 12:10 a.m. 🔄 Last Modified: Aug. 8, 2025, 5:02 p.m.

8.8

CVSS3.1

CVE-2025-23093 -

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an at…

📅 Published: Feb. 6, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2020-36085 -

Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and Last Name in Apply For This Job Form.

📅 Published: Feb. 6, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-36555 -

Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity…

📅 Published: Feb. 6, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-36554 -

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.

📅 Published: Feb. 6, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345359
Page 6449 of 34,536
« previous page » next page
Filters