Medium - CVE-2025-2108 - The 140+ Widgets | Xpro Addons For Elementor –...
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Site Title’ widget's 'title_tag' and...
Critical - CVE-2024-12016 - Improper Neutralization of Special Elements...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0....
NA - CVE-2025-1385 - When the library bridge feature is enabled, the...
When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and...
Critical - CVE-2025-2505 - The Age Gate plugin for WordPress is vulnerable...
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for...
NA - CVE-2024-47552 - Deserialization of Untrusted Data vulnerability...
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Users are recommended to upgrade to version...
NA - CVE-2024-54016 - Improper Handling of Highly Compressed Data...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through
NA - CVE-2024-0245 - A misconfiguration in the AndroidManifest.xml...
A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permissions of the...
NA - CVE-2024-0640 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard...
NA - CVE-2024-10019 - A vulnerability in the `start_app_server`...
A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the...
NA - CVE-2024-10047 - parisneo/lollms-webui versions v9.9 to the...
parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted...