CVE-2024-48590 – Inflectra SpiraTeam SSRF Vulnerability
The following table lists the changes that have been made to the CVE-2024-48590 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]
CVE-2025-29101 – Tenda AC8V4.0 Stack Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-29101 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]
CVE-2025-2311 – Nebula Informatics SecHard Privileged API Abuse and Sensitive Information Exposure
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Nebula Informatics SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring.This issue affects SecHard: before 3.3.0.20220411.
CVE-2025-2539 – WordPress File Away Plugin File Disclosure Vulnerability
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the […]
CVE-2025-27888 – Apache Druid SSRF, XSS and Open Redirect Vulnerability
Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’), URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect […]
CVE-2025-1802 – HT Mega – Absolute Addons For Elementor Stored Cross-Site Scripting
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, ‘notification_content’, and ‘stt_button_text’ parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary […]
CVE-2024-13923 – WooCommerce Server-Side Request Forgery Vulnerability
The following table lists the changes that have been made to the CVE-2024-13923 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]
CVE-2024-13922 – WooCommerce Order Export & Import Arbitrary File Deletion Vulnerability
The following table lists the changes that have been made to the CVE-2024-13922 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]
CVE-2024-13921 – WooCommerce Order Export & Order Import PHP Object Injection Vulnerability
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the ‘form_data’ parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain […]
CVE-2024-13920 – WooCommerce Directory Traversal Vulnerability
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive […]