NA - CVE-2024-57963 - Insecure Loading of Dynamic Link Libraries have...
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on...
NA - CVE-2024-57964 - Insecure Loading of Dynamic Link Libraries have...
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on...
Medium - CVE-2024-11376 - The s2Member – Excellent for All Kinds of...
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use...
Medium - CVE-2024-11895 - The Online Payments – Get Paid with PayPal,...
The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including,...
Medium - CVE-2024-13465 - The aBlocks – WordPress Gutenberg Blocks plugin...
The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" attribute, in all...
Medium - CVE-2024-13575 - The Web Stories Enhancer – Level Up Your Web...
The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in all...
High - CVE-2024-13704 - The Super Testimonials plugin for WordPress is...
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient...
Medium - CVE-2024-13795 - The Ecwid by Lightspeed Ecommerce Shopping Cart...
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect...
NA - CVE-2025-0422 - An authenticated user in the "bestinformed Web"...
An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execution) For this, the user must be able to create...
NA - CVE-2025-0423 - In the "bestinformed Web" application, some...
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is...