NA - CVE-2025-27100 - lakeFS is an open-source tool that transforms...
lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an...
NA - CVE-2025-1001 - Medixant RadiAnt DICOM Viewer is vulnerable due...
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry...
NA - CVE-2024-38657 - External control of a file name in Ivanti...
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to...
Medium - CVE-2024-13235 - The Pinpoint Booking System – #1 WordPress...
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.2...
Medium - CVE-2024-13379 - The C9 Admin Dashboard plugin for WordPress is...
The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and...
Medium - CVE-2024-13388 - The TCBD Tooltip plugin for WordPress is...
The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 due to...
Medium - CVE-2024-13537 - The C9 Blocks plugin for WordPress is...
The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file...
Medium - CVE-2024-13672 - The Mini Course Generator | Embed mini-courses...
The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in all...
Medium - CVE-2024-13751 - The 3D Photo Gallery plugin for WordPress is...
The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all versions up to, and including, 1.3 due to insufficient input...
Medium - CVE-2024-13818 - The Registration Forms – User Registration...
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive...