Medium - CVE-2024-9661 - The WP All Import Pro plugin for WordPress is...
The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.7. This is due to missing nonce validation on the delete_and_edit...
High - CVE-2024-9664 - The WP All Import Pro plugin for WordPress is...
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of untrusted input from an import file. This makes...
NA - CVE-2022-26388 - A use of hard-coded password vulnerability may...
A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting...
NA - CVE-2022-26389 - An improper access control vulnerability may...
An improper access control vulnerability may allow privilege escalation.This issue affects: * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; * ELI 280/BUR280/MLBUR 280...
Medium - CVE-2024-7425 - The WP ALL Export Pro plugin for WordPress is...
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all...
High - CVE-2025-1104 - A vulnerability has been found in D-Link...
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack...
Medium - CVE-2025-1105 - A vulnerability was found in SiberianCMS...
A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of the component...
Medium - CVE-2025-1106 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation...
NA - CVE-2021-27017 - Utilization of a module presented a security...
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.