Medium - CVE-2024-13356 - The DSGVO All in one for WP plugin for...
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the...
Medium - CVE-2024-13510 - The ShopSite plugin for WordPress is vulnerable...
The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This...
Medium - CVE-2024-13529 - The SocialV - Social Network and Community...
The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
Medium - CVE-2024-13733 - The SKT Blocks – Gutenberg based Page Builder...
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions up to, and...
High - CVE-2024-40890 - **UNSUPPORTED WHEN ASSIGNED**
A...
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow...
High - CVE-2024-40891 - **UNSUPPORTED WHEN ASSIGNED**
A...
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615...
NA - CVE-2025-23015 - Privilege Defined With Unsafe Actions...
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via...
NA - CVE-2024-27137 - In Apache Cassandra it is possible for a local...
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack...
Critical - CVE-2025-0890 - **UNSUPPORTED WHEN ASSIGNED**
Insecure default...
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log...
NA - CVE-2025-24860 - Incorrect Authorization vulnerability in Apache...
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or...