Medium - CVE-2025-1483 - The LTL Freight Quotes – GlobalTranz Edition...
The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engtz_wd_save_dropship AJAX endpoint in...
Medium - CVE-2024-49337 - IBM OpenPages with Watson 8.3 and 9.0 IBM...
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email...
Medium - CVE-2024-49344 - IBM OpenPages with Watson 8.3 and 9.0 IBM...
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is...
Medium - CVE-2024-49779 - IBM OpenPages with Watson 8.3 and 9.0 IBM...
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By...
High - CVE-2024-49781 - IBM OpenPages with Watson 8.3 and 9.0 IBM...
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to...
NA - CVE-2025-0868 - A vulnerability, that could result in Remote...
A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python...
Medium - CVE-2025-1043 - The Embed Any Document – Embed PDF, Word,...
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the...
NA - CVE-2025-21105 - Dell RecoverPoint for Virtual Machines 6.0.X...
Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running...
NA - CVE-2025-21106 - Dell Recover Point for Virtual Machines 6.0.X...
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to...
NA - CVE-2025-1039 - The Lenix Elementor Leads addon plugin for...
The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field in all versions up to, and including, 1.8.2 due to insufficient input...