CVE-2024-12857 – AdForest WordPress Authentication Bypass Vulnerability
CVE ID : CVE-2024-12857 Published : Jan. 22, 2025, 7:15 a.m. | 44 minutes ago Description : The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user’s identity prior to logging them in as that user. This […]
CVE-2024-13406 – Google Merchant Center Plugin for WordPress Reflected Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13406 Published : Jan. 22, 2025, 7:15 a.m. | 44 minutes ago Description : The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘feed_id’ parameter in all versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2024-12117 – The Stackable Gutenberg Blocks Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-12117 Published : Jan. 22, 2025, 7:15 a.m. | 44 minutes ago Description : The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output […]
CVE-2025-23237 – “UD-LT2 OS Command Injection Vulnerability”
The following table lists the changes that have been made to the CVE-2025-23237 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 22, 2025 Action […]
CVE-2025-22450 – WiSoka UD-LT2 Firewall Inclusion Vulnerability
The following table lists the changes that have been made to the CVE-2025-22450 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 22, 2025 Action […]
CVE-2025-20617 – Cisco UD-LT2 OS Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-20617 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 22, 2025 Action […]
CVE-2024-12879 – “WordPress WPBot Pro Unauthorized Data Modification – Arbitrary Chat Response Injection”
CVE ID : CVE-2024-12879 Published : Jan. 22, 2025, 6:15 a.m. | 1 hour ago Description : The WPBot Pro WordPress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘qc_wp_latest_update_check_pro’ function in all versions up to, and including, 13.5.5. This makes it possible for authenticated […]
Turning Data into Decisions: How CVE Management Is Changing
Turning Data into Decisions: How CVE Management Is Changing Every day, hundreds of new Common Vulnerabilities and Exposures (CVEs) are published, many of which target critical systems that keep businesses and governments operational. For cybersecurity professi … Read more Published Date: Jan 22, 2025 (2 hours, 13 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-21893 […]
CVE-2024-11218 – Podman/Buildah Compose Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2024-11218 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 22, 2025 Action […]
CVE-2024-13590 – WordPress Ketchup Shortcodes Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13590 Published : Jan. 22, 2025, 4:15 a.m. | 56 minutes ago Description : The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘spacer’ shortcode in all versions up to, and including, 0.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]