High - CVE-2024-13531 - The ShipEngine Shipping Quotes plugin for...
The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.0.7 due to insufficient escaping on...
NA - CVE-2024-32838 - SQL Injection vulnerability in various API...
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject...
Medium - CVE-2025-0506 - The Rise Blocks – A Complete Gutenberg Page...
The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the titleTag parameter in all versions up to, and including, 3.6 due to...
Medium - CVE-2025-1189 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file /admin/chart1.php. The manipulation...
Low - CVE-2025-1190 - A vulnerability has been found in code-projects...
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The...
Medium - CVE-2025-1191 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file...
Medium - CVE-2025-1192 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file select-menu.php. The...
NA - CVE-2025-1230 - Stored Cross-Site Scripting (XSS) vulnerability...
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘//index.php’, affecting the ‘link’ parameter. This vulnerability...
Critical - CVE-2024-10960 - The Brizy – Page Builder plugin for WordPress...
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and...
High - CVE-2024-12386 - The WP Abstracts plugin for WordPress is...
The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This...