NA - CVE-2025-27416 - Scratch-Coding-Hut.github.io is the website for...
Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password form. Any user who used the sign in page would...
NA - CVE-2025-23115 - A Use After Free vulnerability on UniFi Protect...
A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras management network.
NA - CVE-2025-23116 - An Authentication Bypass vulnerability on UniFi...
An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to...
NA - CVE-2025-23117 - An Insufficient Firmware Update Validation...
An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera...
NA - CVE-2025-23118 - An Improper Certificate Validation...
An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.
NA - CVE-2025-23119 - An Improper Neutralization of Escape Sequences...
An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras...
Medium - CVE-2024-13358 - The BuddyPress WooCommerce My Account...
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the...
Medium - CVE-2025-1780 - The BuddyPress WooCommerce My Account...
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the...
Medium - CVE-2024-13518 - The Simple:Press Forum plugin for WordPress is...
The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13559 - The TemplatesNext ToolKit plugin for WordPress...
The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including,...