Medium - CVE-2024-13735 - The HurryTimer – An Scarcity and Urgency...
The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.11.2...
NA - CVE-2024-52577 - In Apache Ignite versions from 2.6.0 and before...
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually...
Medium - CVE-2024-13791 - Bit Assist plugin for WordPress is vulnerable...
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated...
Medium - CVE-2025-0821 - Bit Assist plugin for WordPress is vulnerable...
Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied...
NA - CVE-2025-26522 - This vulnerability exists in RupeeWeb trading...
This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit...
NA - CVE-2025-26523 - This vulnerability exists in RupeeWeb trading...
This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this...
NA - CVE-2025-26524 - This vulnerability exists in RupeeWeb trading...
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by...
NA - CVE-2024-52500 - Missing Authorization vulnerability in...
Missing Authorization vulnerability in monetagwp Monetag Official Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Monetag Official Plugin: from...
NA - CVE-2025-0867 - The standard user uses the run as function to...
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were...