High - CVE-2025-1282 - The Car Dealer Automotive WordPress Theme –...
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car()...
Medium - CVE-2025-1690 - The ThemeMakers Stripe Checkout plugin for...
The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' shortcode in versions up to, and including, 1.0.1 due to insufficient...
Medium - CVE-2024-13734 - The Card Elements for Elementor plugin for...
The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profile Card widget in all versions up to, and including, 1.2.6 due to...
NA - CVE-2024-10918 - Stack-based Buffer Overflow vulnerability in...
Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected...
Medium - CVE-2024-13217 - The Jeg Elementor Kit plugin for WordPress is...
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and...
NA - CVE-2025-1751 - A SQL Injection vulnerability has been found in...
A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in...
Medium - CVE-2024-13402 - The Buddyboss Platform plugin for WordPress is...
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input...
NA - CVE-2025-1691 - The MongoDB Shell may be susceptible to control...
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input and run...
NA - CVE-2025-1692 - The MongoDB Shell may be susceptible to control...
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary...