CVE-2024-55417 – DevDojo Voyager File Upload Code Execution Bypass
The following table lists the changes that have been made to the CVE-2024-55417 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]
CVE-2024-55416 – DevDojo Voyager Reflected Cross-Site Scripting
The following table lists the changes that have been made to the CVE-2024-55416 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]
CVE-2024-55415 – DevDojo Voyager Path Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2024-55415 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]
CVE-2024-53615 – Files.Gallery Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-53615 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 30, 2025 Action […]
CVE-2024-55591 Exploit Code Released for FortiOS Flaw
CVE-2024-55591 Exploit Code Released for FortiOS Flaw Cybersecurity company watchTowr Labs has released the proof-of-concept (PoC) exploit code for a severe zero-day vulnerability, CVE-2024-55591, affecting Fortinet’s FortiOS and FortiProxy products. Thi … Read more Published Date: Jan 30, 2025 (2 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22217 CVE-2025-0065 CVE-2024-55591 CVE-2024-47575
CVE-2024-8494 – Elementor Website Builder Pro WordPress Private Data Exposure
CVE ID : CVE-2024-8494 Published : Jan. 30, 2025, 2:15 p.m. | 1 hour, 53 minutes ago Description : The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the ‘elementor-template’ shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, […]
CVE-2024-13742 – iControlWP WordPress Site Manager PHP Object Injection Vulnerability
CVE ID : CVE-2024-13742 Published : Jan. 30, 2025, 2:15 p.m. | 1 hour, 53 minutes ago Description : The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the reqpars parameter. This makes it possible for […]
CVE-2024-13720 – “WordPress WP Image Uploader Remote File Deletion”
CVE ID : CVE-2024-13720 Published : Jan. 30, 2025, 2:15 p.m. | 1 hour, 53 minutes ago Description : The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers […]
CVE-2024-13715 – “WordPress zStore Manager Basic Plugin Cache Clearance Unauthorized Access”
CVE ID : CVE-2024-13715 Published : Jan. 30, 2025, 2:15 p.m. | 1 hour, 53 minutes ago Description : The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated […]
CVE-2024-13705 – “WordPress StageShow Plugin Reflected Cross-Site Scripting Vulnerability”
CVE ID : CVE-2024-13705 Published : Jan. 30, 2025, 2:15 p.m. | 1 hour, 53 minutes ago Description : The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 9.8.6. This makes it possible for unauthenticated attackers […]