CVE-2024-13540 – WordPress WooODT Lite Full Path Disclosure
The following table lists the changes that have been made to the CVE-2024-13540 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13538 – BigBuy WooCommerce Full Path Disclosure
The following table lists the changes that have been made to the CVE-2024-13538 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13535 – Actionwear WordPress Sync Plugin Full Path Disclosure
The following table lists the changes that have been made to the CVE-2024-13535 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2025-1390 – Libcap PAM Capabilities Group Name Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1390 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13740 – ProfileGrid WordPress Insecure Direct Object Reference
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations […]
CVE-2024-13741 – ProfileGrid WordPress SSRF Vulnerability
CVE ID : CVE-2024-13741 Published : Feb. 18, 2025, 2:15 a.m. | 37 minutes ago Description : The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level […]
CVE-2025-25224 – LuxCal Web Calendar File Inclusion Vulnerability
The following table lists the changes that have been made to the CVE-2025-25224 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2025-25222 – LuxCal SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-25222 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2025-25223 – LuxCal Web Calendar Path Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2025-25223 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2025-25221 – LuxCal Web Calendar SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-25221 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]