CVE-2024-13683 – “Sperse.IO Automate Hub Cross-Site Request Forgery”

CVE ID : CVE-2024-13683 Published : Jan. 24, 2025, 7:15 a.m. | 31 minutes ago Description : The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation on the ‘automate_hub’ page. This makes it […]

CVE-2024-13680 – WordPress Form Builder CP SQL Injection

CVE ID : CVE-2024-13680 Published : Jan. 24, 2025, 7:15 a.m. | 31 minutes ago Description : The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter of the ‘CP_EASY_FORM_WILL_APPEAR_HERE’ shortcode in all versions up to, and including, 1.2.41 due to insufficient escaping on the user supplied parameter and lack […]

CVE-2024-13659 – Listamester for WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-13659 Published : Jan. 24, 2025, 6:15 a.m. | 28 minutes ago Description : The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘listamester’ shortcode in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it […]

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List Vulnerability / JavaScript The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known … Read more Published Date: Jan 24, 2025 (1 hour, 31 minutes ago) Vulnerabilities has been mentioned in this article. […]

CISA adds jQuery CVE-2020-11023 to KEV Catalog

CISA adds jQuery CVE-2020-11023 to KEV Catalog CVE-2020-11023 is a significant security flaw within jQuery, a widely used JavaScript library. The vulnerability is categorized as a persistent cross-site scripting (XSS) issue. This type of vulnerabi … Read more Published Date: Jan 24, 2025 (45 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2025-0314 – GitLab CE/EE Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-0314 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]

CVE-2024-11931 – GitLab CI Variable Exfiltration Vulnerability

The following table lists the changes that have been made to the CVE-2024-11931 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]

CVE-2025-23006 impacts SonicWall SMA 1000 Series

CVE-2025-23006 impacts SonicWall SMA 1000 Series CVE-2025-23006 is a critical pre-authentication deserialization of untrusted data vulnerability identified in SonicWall’s Secure Mobile Access (SMA) 1000 series appliances. This vulnerability poses si … Read more Published Date: Jan 24, 2025 (1 hour, 12 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2021-30745 – Apache Guacamole Command Injection

The following table lists the changes that have been made to the CVE-2021-30745 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Jan. 24, 2025 Action Type […]