Medium - CVE-2024-10970 - The The Motors – Car Dealer, Classifieds &...
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software...
Medium - CVE-2025-0170 - The DWT - Directory & Listing WordPress Theme...
The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping on...
Critical - CVE-2025-0455 - The airPASS from NetVision Information has a...
The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Critical - CVE-2025-0456 - The airPASS from NetVision Information has a...
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all...
High - CVE-2025-0457 - The airPASS from NetVision Information has an...
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.