NA - CVE-2025-5459 - A user with specific node group editing...
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions...
NA - CVE-2024-11584 - cloud-init through 25.1.2 includes the systemd...
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This being used for the...
NA - CVE-2024-6174 - When a non-x86 platform is detected, cloud-init...
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Medium - CVE-2025-5338 - The Royal Elementor Addons plugin for WordPress...
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1024 due to insufficient input...
Medium - CVE-2025-5842 - The Modern Design Library plugin for WordPress...
The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.4 due to insufficient input...
High - CVE-2025-6212 - The Ultra Addons for Contact Form 7 plugin for...
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and...
NA - CVE-2025-3722 - A path traversal vulnerability in System...
A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information...
NA - CVE-2025-3771 - Vulnerability allows local user to write...
Vulnerability allows local user to write registry backup files into another location set by the user by creating junction symlink in System Information Reporter.