Medium - CVE-2024-13521 - The MailUp Auto Subscription plugin for...
The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on...
Medium - CVE-2025-0321 - The ElementsKit Pro plugin for WordPress is...
The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 due to insufficient input...
Medium - CVE-2024-13527 - The Philantro – Donations and Donor Management...
The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and...
NA - CVE-2024-23953 - Use of Arrays.equals() in LlapSignerImpl in...
Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an...
NA - CVE-2025-0290 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions,...
Medium - CVE-2025-0736 - A flaw was found in Infinispan, when using...
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials,...
Medium - CVE-2025-0750 - A vulnerability was found in CRI-O. A path...
A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to...
Medium - CVE-2025-0752 - A flaw was found in OpenShift Service Mesh...
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header...
Medium - CVE-2025-0754 - The vulnerability was found in OpenShift...
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of...
NA - CVE-2025-0065 - Improper Neutralization of Argument Delimiters...
Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on a...