CVE-2024-48590 – Inflectra SpiraTeam SSRF Vulnerability

The following table lists the changes that have been made to the CVE-2024-48590 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2025-29101 – Tenda AC8V4.0 Stack Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-29101 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2025-2539 – WordPress File Away Plugin File Disclosure Vulnerability

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the […]

CVE-2025-27888 – Apache Druid SSRF, XSS and Open Redirect Vulnerability

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’), URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect […]

CVE-2025-1802 – HT Mega – Absolute Addons For Elementor Stored Cross-Site Scripting

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, ‘notification_content’, and ‘stt_button_text’ parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary […]

CVE-2024-13923 – WooCommerce Server-Side Request Forgery Vulnerability

The following table lists the changes that have been made to the CVE-2024-13923 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-13922 – WooCommerce Order Export & Import Arbitrary File Deletion Vulnerability

The following table lists the changes that have been made to the CVE-2024-13922 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 20, 2025 Action […]

CVE-2024-13920 – WooCommerce Directory Traversal Vulnerability

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive […]