High - CVE-2025-6814 - The Booking X plugin for WordPress is...
The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in versions 1.0 to 1.1.2. This makes it possible for...
Medium - CVE-2025-7046 - The Portfolio for Elementor & Image Gallery |...
The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS Attributes of Plugin's widgets in all versions up...
Low - CVE-2025-7053 - A vulnerability was found in Cockpit up to...
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument...
Medium - CVE-2025-5372 - A flaw was found in libssh versions built with...
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return...
Medium - CVE-2025-6944 - The Uncode Core plugin for WordPress is...
The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and 'uncode_text_icon' shortcodes in all versions up to,...
Medium - CVE-2024-11937 - The Premium Addons for Elementor plugin for...
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's linkURL in the Mobile Menu element in all versions up to, and including,...
Medium - CVE-2025-6673 - The Easy restaurant menu manager plugin for...
The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_eprm_menu_link shortcode in versions up to, and including 2.0.1, due to...