CVE-2025-1271 – Anapi Group’s h6web Reflected Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2025-1271 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 13, 2025 Action […]
CVE-2025-1270 – Anapi Group h6web IDOR
The following table lists the changes that have been made to the CVE-2025-1270 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 13, 2025 Action […]
CVE-2025-1094 – PostgreSQL SQL Injection Vulnerability
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL […]
CVE-2024-13182 – WordPress Directorybox Manager Authentication Bypass
The following table lists the changes that have been made to the CVE-2024-13182 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 13, 2025 Action […]
CVE-2025-21700 – Linux Kernel Net_sched UAF Privilege Escalation
The following table lists the changes that have been made to the CVE-2025-21700 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Feb. 13, 2025 Action […]
CVE-2024-13867 – Listivo WordPress Theme – Reflected Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13867 Published : Feb. 13, 2025, 10:15 a.m. | 45 minutes ago Description : The Listivo – Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all versions up to, and including, 2.3.67 due to insufficient input sanitization and output escaping. This makes it […]
CVE-2024-13606 – WordPress JS Help Desk Sensitive Information Exposure
CVE ID : CVE-2024-13606 Published : Feb. 13, 2025, 10:15 a.m. | 45 minutes ago Description : The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the ‘jssupportticketdata’ directory. This makes it possible for unauthenticated […]
CVE-2024-46910 – Apache Atlas Cross-Site Scripting (XSS) and Authorization Bypass
The following table lists the changes that have been made to the CVE-2024-46910 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 13, 2025 Action […]
CVE-2024-3303 – GitLab EE: Private Issue Exfiltration via Prompt Injection
The following table lists the changes that have been made to the CVE-2024-3303 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 13, 2025 Action […]
CVE-2024-13639 – WordPress Read More & Accordion Plugin Unauthorized Data Deletion Vulnerability
CVE ID : CVE-2024-13639 Published : Feb. 13, 2025, 9:15 a.m. | 1 hour, 45 minutes ago Description : The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it […]