CVE-2024-13545 – “WordPress Bootstrap Ultimate Remote File Inclusion Vulnerability”
CVE ID : CVE-2024-13545 Published : Jan. 24, 2025, 9:15 a.m. | 31 minutes ago Description : The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing […]
CVE-2024-13683 – “Sperse.IO Automate Hub Cross-Site Request Forgery”
CVE ID : CVE-2024-13683 Published : Jan. 24, 2025, 7:15 a.m. | 31 minutes ago Description : The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation on the ‘automate_hub’ page. This makes it […]
CVE-2024-13680 – WordPress Form Builder CP SQL Injection
CVE ID : CVE-2024-13680 Published : Jan. 24, 2025, 7:15 a.m. | 31 minutes ago Description : The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter of the ‘CP_EASY_FORM_WILL_APPEAR_HERE’ shortcode in all versions up to, and including, 1.2.41 due to insufficient escaping on the user supplied parameter and lack […]
CVE-2024-13659 – Listamester for WordPress Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13659 Published : Jan. 24, 2025, 6:15 a.m. | 28 minutes ago Description : The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘listamester’ shortcode in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it […]
CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List
CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List Vulnerability / JavaScript The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known … Read more Published Date: Jan 24, 2025 (1 hour, 31 minutes ago) Vulnerabilities has been mentioned in this article. […]
CISA adds jQuery CVE-2020-11023 to KEV Catalog
CISA adds jQuery CVE-2020-11023 to KEV Catalog CVE-2020-11023 is a significant security flaw within jQuery, a widely used JavaScript library. The vulnerability is categorized as a persistent cross-site scripting (XSS) issue. This type of vulnerabi … Read more Published Date: Jan 24, 2025 (45 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2025-0314 – GitLab CE/EE Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-0314 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2024-11931 – GitLab CI Variable Exfiltration Vulnerability
The following table lists the changes that have been made to the CVE-2024-11931 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 24, 2025 Action […]
CVE-2025-23006 impacts SonicWall SMA 1000 Series
CVE-2025-23006 impacts SonicWall SMA 1000 Series CVE-2025-23006 is a critical pre-authentication deserialization of untrusted data vulnerability identified in SonicWall’s Secure Mobile Access (SMA) 1000 series appliances. This vulnerability poses si … Read more Published Date: Jan 24, 2025 (1 hour, 12 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2021-30745 – Apache Guacamole Command Injection
The following table lists the changes that have been made to the CVE-2021-30745 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Jan. 24, 2025 Action Type […]