High - CVE-2025-1648 - The Yawave plugin for WordPress is vulnerable...
The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied...
NA - CVE-2025-1673 - A malicious or malformed DNS packet without a...
A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation.
Medium - CVE-2024-13494 - The WordPress File Upload plugin for WordPress...
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the...
NA - CVE-2025-1675 - The function dns_copy_qname in dns_pack.c...
The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is large enough to contain the copied data.
Medium - CVE-2024-13693 - The Enfold theme for WordPress is vulnerable to...
The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it...
Medium - CVE-2024-13695 - The Enfold theme for WordPress is vulnerable to...
The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes it possible for...
NA - CVE-2025-1676 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2swf of the file /pdf2swf. The manipulation of...
Medium - CVE-2025-1262 - The Advanced Google reCaptcha plugin for...
The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the...
NA - CVE-2024-51539 - The Dell Secure Connect Gateway (SCG)...
The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL...