High - CVE-2025-0924 - The WP Activity Log plugin for WordPress is...
The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization...
Low - CVE-2025-1376 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The...
Low - CVE-2025-1377 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The...
High - CVE-2025-1389 - Orca HCM from Learning Digital has a SQL...
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
NA - CVE-2024-13603 - The Wise Forms WordPress plugin through 1.2.0...
The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious...
NA - CVE-2024-13608 - The Track Logins WordPress plugin through 1.0...
The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
NA - CVE-2024-13625 - The Tube Video Ads Lite WordPress plugin...
The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be...
NA - CVE-2024-13626 - The VR-Frases (collect & share quotes)...
The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting...
NA - CVE-2024-13627 - The OWL Carousel Slider WordPress plugin...
The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-13726 - The Coder WordPress plugin through 1.3.4 does...
The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a...