CVE-2024-13667 – “Uncode for WordPress Stored Cross-Site Scripting Vulnerability”
The following table lists the changes that have been made to the CVE-2024-13667 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13636 – Brooklyn Theme for WordPress PHP Object Injection Vulnerability
The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.9.2 via deserialization of untrusted input in the ot_decode function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, […]
CVE-2025-1023 – ChurchCRM SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1023 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by b7efe717-a805-47cf-8e9a-921fca0ce0ce Feb. 18, 2025 Action […]
CVE-2025-0981 – ChurchCRM Stored Cross Site Scripting (XSS) Sessions Hijacking
The following table lists the changes that have been made to the CVE-2025-0981 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by b7efe717-a805-47cf-8e9a-921fca0ce0ce Feb. 18, 2025 Action […]
CVE-2024-13369 – Tour Master WordPress Tour Booking SQL Injection Vulnerability
CVE ID : CVE-2024-13369 Published : Feb. 18, 2025, 10:15 a.m. | 39 minutes ago Description : The Tour Master – Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insufficient escaping on the user supplied parameter and […]
OpenSSH Flaws CVE-2025-26465 & CVE-2025-26466 Expose Clients and Servers to Attacks
OpenSSH Flaws CVE-2025-26465 & CVE-2025-26466 Expose Clients and Servers to Attacks The Qualys Threat Research Unit (TRU) has disclosed two newly identified vulnerabilities in OpenSSH, affecting both clients and servers. These flaws, tracked as CVE-2025-26465 and CVE-2025-26466, coul … Read more Published Date: Feb 18, 2025 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this […]
CVE-2024-13718 – WooCommerce Flexible Wishlist CSRF Vulnerability
The following table lists the changes that have been made to the CVE-2024-13718 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13395 – WordPress Threepress Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2024-13395 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13316 – WordPress Scratch & Win Coupon Creation Remote Authentication Bypass Vulnerability
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the apmswn_create_discount() function in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create coupons.
CVE-2024-12860 – CarSpot – Dealership WordPress Classified Theme WordPress Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2024-12860 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]