CVE-2024-10799 – WordPress Eventer Directory Traversal Vulnerability
CVE ID : CVE-2024-10799 Published : Jan. 17, 2025, 6:15 a.m. | 29 minutes ago Description : The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of […]
CVE-2024-13434 – “WordPress WP Inventory Manager Reflected Cross-Site Scripting Vulnerability”
CVE ID : CVE-2024-13434 Published : Jan. 17, 2025, 5:15 a.m. | 31 minutes ago Description : The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated […]
CVE-2024-13401 – “PayPal WordPress Stored Cross-Site Scripting Vulnerability”
CVE ID : CVE-2024-13401 Published : Jan. 17, 2025, 5:15 a.m. | 31 minutes ago Description : The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘wp_paypal_checkout’ shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. […]
CVE-2024-13398 – PayPal Checkout for WordPress Stored Cross-Site Scripting
CVE ID : CVE-2024-13398 Published : Jan. 17, 2025, 5:15 a.m. | 31 minutes ago Description : The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘checkout_for_paypal’ shortcode in all versions up to, and including, 1.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This […]
CVE-2024-51462 – IBM QRadar WinCollect Agent XML Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-51462 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw
CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw Security researcher c411e published a proof-of-concept (PoC) exploit code for a severe vulnerability in QNAP NAS devices, identified as CVE-2024-53691, with a CVSS score of 8.7. Exploitation of this f … Read more Published Date: Jan 17, 2025 (1 hour, 44 minutes ago) Vulnerabilities has been mentioned in […]
Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package
Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package Yubico, a leading provider of security keys and authentication solutions, has issued a security advisory to address an authentication bypass vulnerability, CVE-2025-23013, in their open-source pam-u2f … Read more Published Date: Jan 17, 2025 (1 hour, 52 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-23013
HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems
HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems HPE Aruba Networking has issued a security advisory addressing multiple vulnerabilities in its ArubaOS (AOS) systems, which are widely deployed in enterprise networks to manage Mobility Conductors, Co … Read more Published Date: Jan 17, 2025 (55 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-42911 […]
CVE-2024-52363 – IBM InfoSphere Information Server Directory Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2024-52363 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2025-23082 impacts Veeam Backup for Microsoft Azure
CVE-2025-23082 impacts Veeam Backup for Microsoft Azure CVE-2025-23082 is a high-severity security vulnerability identified in Veeam Backup for Microsoft Azure, a solution designed to protect workloads running in Microsoft’s Azure cloud environment. This v … Read more Published Date: Jan 17, 2025 (1 hour, 1 minute ago) Vulnerabilities has been mentioned in this article. CVE-2023-37936 CVE-2025-23082 CVE-2024-50603 […]