Medium - CVE-2025-4420 - The Vayu Blocks – Gutenberg Blocks for...
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and...
Medium - CVE-2025-5103 - The Ultimate Gift Cards for WooCommerce plugin...
The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'default_price' and 'product_id' parameters in all versions up...
Medium - CVE-2025-5116 - The WP Plugin Info Card plugin for WordPress is...
The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, 5.3.1 due to insufficient input...
NA - CVE-2024-36486 - A privilege escalation vulnerability exists in...
A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is...
NA - CVE-2024-52561 - A privilege escalation vulnerability exists in...
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service...
NA - CVE-2024-54189 - A privilege escalation vulnerability exists in...
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service...
NA - CVE-2025-31359 - A directory traversal vulnerability exists in...
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to...
High - CVE-2025-4392 - The Shared Files – Frontend File Upload Form &...
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including,...
Medium - CVE-2025-5492 - A vulnerability has been found in D-Link...
A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnerability is the function sub_456DE8 of the file /msp_info.htm?flag=cmd of the...
Medium - CVE-2025-5493 - A vulnerability was found in Baison Channel...
A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file...