CVE-2024-13041 – GitLab SAML Provider External Group Configuration Bypass Vulnerability
The following table lists the changes that have been made to the CVE-2024-13041 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2025-0335 – Apache Code-projects Online Bike Rental System Arbitrary File Upload Vulnerability
The following table lists the changes that have been made to the CVE-2025-0335 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2025-0334 – Leiyuxi Cy-Fast SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-0334 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2024-6324 – GitLab DoS (Denial of Service) – Cyclic Epic Reference
The following table lists the changes that have been made to the CVE-2024-6324 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2024-12736 – WordPress BU Section Editing Reflected Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-12736 Published : Jan. 9, 2025, 6:15 a.m. | 26 minutes ago Description : The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. […]
CVE-2024-12731 – Aklamator INfeed WordPress Reflected Cross-Site Scripting
CVE ID : CVE-2024-12731 Published : Jan. 9, 2025, 6:15 a.m. | 26 minutes ago Description : The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. Severity: […]
CVE-2024-12717 – Aklamator INfeed WordPress Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-12717 Published : Jan. 9, 2025, 6:15 a.m. | 26 minutes ago Description : The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for […]
CVE-2024-12715 – WordPress Asgard Security Scanner Reflected Cross-Site Scripting
CVE ID : CVE-2024-12715 Published : Jan. 9, 2025, 6:15 a.m. | 26 minutes ago Description : The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. […]
CVE-2024-12714 – Apache Backlink Monitoring Manager Reflected Cross-Site Scripting
CVE ID : CVE-2024-12714 Published : Jan. 9, 2025, 6:15 a.m. | 26 minutes ago Description : The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. […]
CVE-2024-10815 – WordPress PostLists ostrov Reflected Cross-Site Scripting
CVE ID : CVE-2024-10815 Published : Jan. 9, 2025, 6:15 a.m. | 26 minutes ago Description : The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER[‘REQUEST_URI’] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers Severity: 0.0 | NA Visit the link for more […]