Critical - CVE-2025-7340 - The HT Contact Form Widget For Elementor Page...
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
Critical - CVE-2025-7341 - The HT Contact Form Widget For Elementor Page...
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in...
Critical - CVE-2025-7360 - The HT Contact Form Widget For Elementor Page...
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the...
Medium - CVE-2025-7367 - The Strong Testimonials plugin for WordPress is...
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input...
NA - CVE-2025-3621 - Vulnerabilities* in ActADUR local server...
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special...
NA - CVE-2025-7672 - The improper default setting in JiranSoft...
The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.
NA - CVE-2025-24477 - A heap-based buffer overflow in Fortinet...
A heap-based buffer overflow in Fortinet FortiOS versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2.4 through 7.2.11 allows an attacker to escalate its privileges via a specially crafted CLI...
Medium - CVE-2025-4369 - The Companion Auto Update plugin for WordPress...
The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ parameter in all versions up to, and including, 3.9.2 due to insufficient...
High - CVE-2025-7667 - The Restrict File Access plugin for WordPress...
The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the...
NA - CVE-2025-34068 - An unauthenticated remote command execution...
An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input validation in the “Tech Support” diagnostic...