CVE-2024-13474 – Purolator LTL Freight Quotes WordPress Plugin SQL Injection Vulnerability
CVE ID : CVE-2024-13474 Published : Feb. 22, 2025, 5:15 a.m. | 37 minutes ago Description : The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the ‘dropship_edit_id’ and ‘edit_id’ parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and […]
Salt Typhoon Hackers Exploit Cisco Vulnerability To Gain Access To U.S. Telecom Networks
Salt Typhoon Hackers Exploit Cisco Vulnerability To Gain Access To U.S. Telecom Networks Cisco Talos has uncovered a sophisticated cyberespionage campaign by the state-aligned “Salt Typhoon” group targeting U.S. telecommunications infrastructure since late 2024. While credential theft rem … Read more Published Date: Feb 22, 2025 (2 hours, 23 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2025-1510 – WordPress Custom Post Type Date Archives Shortcode Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-1510 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 22, 2025 Action […]
CVE-2025-1509 – WordPress Show Me The Cookies Plugin Shortcode Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1509 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 22, 2025 Action […]
CVE-2024-13899 – WordPress Mambo Importer PHP Object Injection Vulnerability
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is […]
CVE-2024-13873 – “WP Job Portal Insecure Direct Object Reference Vulnerability”
The following table lists the changes that have been made to the CVE-2024-13873 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 22, 2025 Action […]
CVE-2023-4261 – Apache HTTP Server Information Disclosure
The following table lists the changes that have been made to the CVE-2023-4261 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Feb. 22, 2025 Action Type […]
CVE-2024-56000 (CVSS 9.8): Account Takeover Flaw in KLEO WordPress Theme
CVE-2024-56000 (CVSS 9.8): Account Takeover Flaw in KLEO WordPress Theme A critical vulnerability has been discovered in the KLEO WordPress theme, potentially allowing attackers to take over user accounts. The vulnerability, tracked as CVE-2024-56000 and assigned a CVSS sc … Read more Published Date: Feb 22, 2025 (1 hour, 42 minutes ago) Vulnerabilities has been mentioned in […]
CVE-2024-22341 – IBM Watson Query on Cloud Pak for Data Privilege Management Vulnerability
The following table lists the changes that have been made to the CVE-2024-22341 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 22, 2025 Action […]
Publicly Disclosed Exploits Put D-Link DIR-823 Users in Danger – No Security Fixes
Publicly Disclosed Exploits Put D-Link DIR-823 Users in Danger – No Security Fixes D-Link has issued a security advisory concerning multiple vulnerabilities affecting the DIR-823 wireless router, revision A1, running firmware version 1.20B07. These vulnerabilities include stack-base … Read more Published Date: Feb 22, 2025 (2 hours, 28 minutes ago) Vulnerabilities has been mentioned in this article. […]