NA - CVE-2024-42191 - HCL Traveler for Microsoft Outlook (HTMO) is...
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
High - CVE-2025-5356 - A vulnerability was found in FreeFloat FTP...
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer...
Medium - CVE-2025-5142 - The Simple Page Access Restriction plugin for...
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and...
Medium - CVE-2025-5235 - The OpenSheetMusicDisplay plugin for WordPress...
The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input...
NA - CVE-2025-1763 - An issue has been discovered in GitLab EE that...
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions...
Medium - CVE-2025-4597 - The Woo Slider Pro – Drag Drop Slider Builder...
The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2025-4944 - The LA-Studio Element Kit for Elementor plugin...
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and...
High - CVE-2025-5190 - The Browse As plugin for WordPress is...
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checking in the...
NA - CVE-2025-1484 - A vulnerability exists in the media upload...
A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system....
NA - CVE-2025-2500 - A vulnerability exists in the SOAP Web services...
A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window...