Medium - CVE-2024-13644 - The DethemeKit For Elementor plugin for...
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to...
NA - CVE-2025-0896 - Orthanc server prior to version 1.5.8 does not...
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
NA - CVE-2025-1198 - An issue discovered in GitLab CE/EE affecting...
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially...
Critical - CVE-2024-10763 - The Campress theme for WordPress is vulnerable...
The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it...
Medium - CVE-2024-13227 - The Rank Math SEO – AI SEO Tools to Dominate...
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including,...
Medium - CVE-2024-13229 - The Rank Math SEO – AI SEO Tools to Dominate...
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all...
High - CVE-2024-13770 - The Puzzles | WP Magazine / Review with Store...
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of...
Medium - CVE-2025-0837 - The Puzzles theme for WordPress is vulnerable...
The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on...
NA - CVE-2024-10083 - CWE-20: Improper Input Validation vulnerability...
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with...
NA - CVE-2024-12586 - The Chalet-Montagne.com Tools WordPress plugin...
The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could...