High - CVE-2024-13655 - The Flex Mag - Responsive WordPress News Theme...
The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the...
Critical - CVE-2025-1475 - The WPCOM Member plugin for WordPress is...
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone'...
NA - CVE-2024-12576 - Software installed and run as a non-privileged...
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output.
High - CVE-2024-13906 - The Gallery by BestWebSoft – Customizable Image...
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via...
Medium - CVE-2025-0863 - The Flexmls® IDX Plugin plugin for WordPress is...
The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to...
High - CVE-2025-1309 - The UiPress lite | Effortless custom...
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a...
NA - CVE-2025-26331 - Dell ThinOS 2411 and prior, contains an...
Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access...
NA - CVE-2025-27816 - A vulnerability was discovered in the Arctera...
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The...
High - CVE-2024-10804 - The Ultimate Video Player WordPress &...
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file....