Medium - CVE-2024-10322 - The Brizy – Page Builder plugin for WordPress...
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 2.6.8 due to insufficient input...
NA - CVE-2025-1197 - A vulnerability has been found in code-projects...
A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file...
Medium - CVE-2025-1199 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been classified as critical. This affects an unknown part of the file /admin/app/role_crud.php. The...
NA - CVE-2024-23563 - HCL Connections Docs is vulnerable to a...
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
NA - CVE-2024-57951 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: hrtimers: Handle CPU state correctly on hotplug Consider a scenario where a CPU transitions from CPUHP_ONLINE to halfway...
NA - CVE-2024-57952 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: Revert "libfs: fix infinite directory reads for offset dir" The current directory offset allocator (based on...
NA - CVE-2025-1100 - A CWE-259 "Use of Hard-coded Password" for the...
A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root...
NA - CVE-2025-1101 - A CWE-204 "Observable Response Discrepancy" in...
A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enumerate valid usernames via...
NA - CVE-2025-1102 - A CWE-346 "Origin Validation Error" in the CORS...
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality,...
Medium - CVE-2025-1200 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/app/slider_crud.php....