Medium - CVE-2024-12276 - The Ultimate Member – User Profile,...
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in...
Medium - CVE-2024-12452 - The Ziggeo plugin for WordPress is vulnerable...
The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode in all versions up to, and including, 3.1 due to insufficient...
High - CVE-2024-13353 - The Responsive Addons for Elementor – Free...
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via...
Medium - CVE-2024-13461 - The Autoship Cloud for WooCommerce Subscription...
The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action'...
Medium - CVE-2024-13648 - The Maps for WP plugin for WordPress is...
The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortcode in all versions up to, and including, 1.2.4 due to...
NA - CVE-2025-1470 - In Eclipse OMR, from the initial contribution...
In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory...
NA - CVE-2025-1471 - In Eclipse OMR versions 0.2.0 to 0.4.0, some of...
In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer...
Medium - CVE-2024-13455 - The igumbi Online Booking plugin for WordPress...
The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_calendar' shortcode in all versions up to, and including, 1.40...
Medium - CVE-2024-13713 - The WPExperts Square For GiveWP plugin for...
The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on...
Medium - CVE-2024-13846 - The Indeed Ultimate Learning Pro plugin for...
The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on...