CVE-2025-0435 – Google Chrome Android UI Spoofing Vulnerability
The following table lists the changes that have been made to the CVE-2025-0435 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 15, 2025 Action […]
CVE-2025-0193 – MGate XSS Stored login.csangen
The following table lists the changes that have been made to the CVE-2025-0193 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 15, 2025 Action […]
CVE-2024-9636 – “Post Grid and Gutenberg Blocks WordPress Administrator Registration Privilege Escalation Vulnerability”
CVE ID : CVE-2024-9636 Published : Jan. 15, 2025, 10:15 a.m. | 27 minutes ago Description : The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes […]
CVE-2024-13351 – “Repuso WordPress Stored Cross-Site Scripting”
CVE ID : CVE-2024-13351 Published : Jan. 15, 2025, 10:15 a.m. | 27 minutes ago Description : The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘rw_image_badge1’ shortcode in all versions up to, and including, 5.20 due to insufficient input sanitization and output escaping on […]
CVE-2024-12818 – The WP Smart TV plugin for WordPress is vulnerable
CVE ID : CVE-2024-12818 Published : Jan. 15, 2025, 10:15 a.m. | 27 minutes ago Description : The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘tv-video-player’ shortcode in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This […]
CVE-2024-12423 – “Contact Form 7 Redirect & Thank You Page Reflected Cross-Site Scripting”
CVE ID : CVE-2024-12423 Published : Jan. 15, 2025, 10:15 a.m. | 27 minutes ago Description : The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This […]
CVE-2024-12297 – Moxa EDS-508A Series Authentication Bypass Vulnerability
The following table lists the changes that have been made to the CVE-2024-12297 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 15, 2025 Action […]
CVE-2024-12403 – “Apache Word Press Image Gallery Reflected Cross-Site Scripting Vulnerability”
CVE ID : CVE-2024-12403 Published : Jan. 15, 2025, 10:15 a.m. | 27 minutes ago Description : The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘awsmgallery’ parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it […]
CVE-2024-10775 – Piotnet Addons For Elementor Information Exposure Vulnerability
CVE ID : CVE-2024-10775 Published : Jan. 15, 2025, 10:15 a.m. | 27 minutes ago Description : The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the ‘pafe-template’ shortcode due to insufficient restrictions on which posts can be included. This makes it possible […]
Ivanti waarschuwt voor kritieke path traversal-lekken in Endpoint Manager
Ivanti waarschuwt voor kritieke path traversal-lekken in Endpoint Manager Softwarebedrijf Ivanti waarschuwt klanten voor kritieke path traversal-kwetsbaarheden in Ivanti Endpoint Manager waardoor een ongeauthenticeerde aanvaller op afstand gevoelige informatie van organisat … Read more Published Date: Jan 15, 2025 (1 hour, 2 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-13161 CVE-2024-13160 CVE-2024-13159 CVE-2024-10811