NA - CVE-2025-22205 - Improper handling of input variables lead to...
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
Medium - CVE-2024-13403 - The WPForms – Easy Form Builder for WordPress –...
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all...
Medium - CVE-2024-13356 - The DSGVO All in one for WP plugin for...
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the...
Medium - CVE-2024-13510 - The ShopSite plugin for WordPress is vulnerable...
The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This...
Medium - CVE-2024-13529 - The SocialV - Social Network and Community...
The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
Medium - CVE-2024-13733 - The SKT Blocks – Gutenberg based Page Builder...
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions up to, and...
High - CVE-2024-40890 - **UNSUPPORTED WHEN ASSIGNED**
A...
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow...
High - CVE-2024-40891 - **UNSUPPORTED WHEN ASSIGNED**
A...
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615...
NA - CVE-2025-23015 - Privilege Defined With Unsafe Actions...
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via...
NA - CVE-2024-27137 - In Apache Cassandra it is possible for a local...
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack...