CVE-2025-0739 – EmbedAI Improper Access Control Vulnerability

The following table lists the changes that have been made to the CVE-2025-0739 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]

CVE-2025-0741 – EmbedAI Improper Access Control Vulnerability

The following table lists the changes that have been made to the CVE-2025-0741 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]

CVE-2024-13706 – WordPress WP Image Uploader Reflected Cross-Site Scripting

CVE ID : CVE-2024-13706 Published : Jan. 30, 2025, 11:15 a.m. | 45 minutes ago Description : The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘file’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated […]

CVE-2024-12524 – Clinked Client Portal for WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-12524 Published : Jan. 30, 2025, 11:15 a.m. | 45 minutes ago Description : The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘clinked-login-button’ shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This […]

CVE-2024-12409 – Simple:Press Forum WordPress Reflected Cross-Site Scripting

CVE ID : CVE-2024-12409 Published : Jan. 30, 2025, 11:15 a.m. | 45 minutes ago Description : The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers […]

CVE-2025-23007 – Citrix NetExtender Windows Unauthenticated System File Access Vulnerability

The following table lists the changes that have been made to the CVE-2025-23007 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]

CVE-2025-21107 – Dell NetWorker Unquoted Search Path Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-21107 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]

CVE-2025-0861 – WordPress VR-Frases Plugin SQL Injection Vulnerability

CVE ID : CVE-2025-0861 Published : Jan. 30, 2025, 10:15 a.m. | 1 hour, 45 minutes ago Description : The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient […]