CVE-2025-0450 – Betheme for WordPress Stored Cross-Site Scripting

CVE ID : CVE-2025-0450 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]

CVE-2024-52973 – “Kibana Observability-Logs Denial of Service Vulnerability”

The following table lists the changes that have been made to the CVE-2024-52973 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]

CVE-2024-43709 – Elasticsearch Resource Allocation Denial of Service

The following table lists the changes that have been made to the CVE-2024-43709 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]

CVE-2024-37284 – Elastic Defend Windows Alt Encoding Crash Vulnerability (Heap Corruption)

The following table lists the changes that have been made to the CVE-2024-37284 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]

CVE-2024-13444 – WordPress wp-greet CSRF

CVE ID : CVE-2024-13444 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to […]

CVE-2024-13230 – WordPress Super Socializer Limited SQL Injection Vulnerability

CVE ID : CVE-2024-13230 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14 due to insufficient escaping on the […]

High Severity Vulnerability Discovered in CP Plus Router: Immediate Attention Needed

High Severity Vulnerability Discovered in CP Plus Router: Immediate Attention Needed A security vulnerability has been identified in the CP Plus CP-XR-DE21-S Router, which could potentially expose sensitive user information and compromise system integrity. This CP Plus Router vulnerab … Read more Published Date: Jan 21, 2025 (1 hour, 31 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-23184 – Apache CXF DoS Denial of Service

The following table lists the changes that have been made to the CVE-2025-23184 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]

CVE-2024-13404 – WordPress Link Library Plugin Reflected Cross-Site Scripting

CVE ID : CVE-2024-13404 Published : Jan. 21, 2025, 10:15 a.m. | 26 minutes ago Description : The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers […]