CVE-2025-0450 – Betheme for WordPress Stored Cross-Site Scripting
CVE ID : CVE-2025-0450 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]
CVE-2024-52973 – “Kibana Observability-Logs Denial of Service Vulnerability”
The following table lists the changes that have been made to the CVE-2024-52973 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]
CVE-2024-43709 – Elasticsearch Resource Allocation Denial of Service
The following table lists the changes that have been made to the CVE-2024-43709 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]
CVE-2024-37284 – Elastic Defend Windows Alt Encoding Crash Vulnerability (Heap Corruption)
The following table lists the changes that have been made to the CVE-2024-37284 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]
CVE-2024-13444 – WordPress wp-greet CSRF
CVE ID : CVE-2024-13444 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to […]
CVE-2024-13230 – WordPress Super Socializer Limited SQL Injection Vulnerability
CVE ID : CVE-2024-13230 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14 due to insufficient escaping on the […]
CVE-2024-11226 – FireCask Like & Share Button Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-11226 Published : Jan. 21, 2025, 11:15 a.m. | 41 minutes ago Description : The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible […]
High Severity Vulnerability Discovered in CP Plus Router: Immediate Attention Needed
High Severity Vulnerability Discovered in CP Plus Router: Immediate Attention Needed A security vulnerability has been identified in the CP Plus CP-XR-DE21-S Router, which could potentially expose sensitive user information and compromise system integrity. This CP Plus Router vulnerab … Read more Published Date: Jan 21, 2025 (1 hour, 31 minutes ago) Vulnerabilities has been mentioned in […]
CVE-2025-23184 – Apache CXF DoS Denial of Service
The following table lists the changes that have been made to the CVE-2025-23184 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 21, 2025 Action […]
CVE-2024-13404 – WordPress Link Library Plugin Reflected Cross-Site Scripting
CVE ID : CVE-2024-13404 Published : Jan. 21, 2025, 10:15 a.m. | 26 minutes ago Description : The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers […]