CVE-2025-0103 – Palo Alto Networks Expedition SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-0103 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]

CVE-2024-42168 – HCL MyXalytics HTTP Request Hijacking Vulnerability

The following table lists the changes that have been made to the CVE-2024-42168 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]

CVE-2024-12627 – WooCommerce Popups PHP Object Injection Vulnerability

CVE ID : CVE-2024-12627 Published : Jan. 11, 2025, 3:15 a.m. | 32 minutes ago Description : The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.5 via deserialization of untrusted input from post […]

CVE-2024-42169 – HCL MyXalytics Insecure Direct Object Reference

The following table lists the changes that have been made to the CVE-2024-42169 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 11, 2025 Action […]

CVE-2024-12505 – WordPress Trackserver Plugin Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-12505 Published : Jan. 11, 2025, 3:15 a.m. | 32 minutes ago Description : The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘tsmap’ shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it […]

CVE-2024-12472 – WordPress Post Duplicator Information Exposure Vulnerability

CVE ID : CVE-2024-12472 Published : Jan. 11, 2025, 3:15 a.m. | 32 minutes ago Description : The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, […]

CVE-2024-12404 – WordPress CF Internal Link Shortcode SQL Injection Vulnerability

CVE ID : CVE-2024-12404 Published : Jan. 11, 2025, 3:15 a.m. | 32 minutes ago Description : The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the ‘post_title’ parameter in all versions up to, and including, 1.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation […]

CVE-2024-12204 – WooCommerce Coupon X Unauthenticated Access Bypass

CVE ID : CVE-2024-12204 Published : Jan. 11, 2025, 3:15 a.m. | 32 minutes ago Description : The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in the class-cx-rest.php file in all versions up […]

CVE-2024-11327 – WordPress ClickWhale Link Manager Reflected Cross-Site Scripting

CVE ID : CVE-2024-11327 Published : Jan. 11, 2025, 3:15 a.m. | 32 minutes ago Description : The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL […]

CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published

CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published A severe security vulnerability has been discovered in several Netgear routers, allowing remote attackers to gain unauthorized access and control over the devices. The vulnerability, identified as CVE … Read more Published Date: Jan 11, 2025 (53 minutes ago) Vulnerabilities has been […]