NA - CVE-2024-23589 - Due to outdated Hash algorithm, HCL Glovius...
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs
NA - CVE-2024-42190 - HCL Traveler for Microsoft Outlook (HTMO) is...
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
NA - CVE-2024-42191 - HCL Traveler for Microsoft Outlook (HTMO) is...
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
High - CVE-2025-5356 - A vulnerability was found in FreeFloat FTP...
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer...
Medium - CVE-2025-5142 - The Simple Page Access Restriction plugin for...
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and...
Medium - CVE-2025-5235 - The OpenSheetMusicDisplay plugin for WordPress...
The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input...
NA - CVE-2025-1763 - An issue has been discovered in GitLab EE that...
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions...
Medium - CVE-2025-4597 - The Woo Slider Pro – Drag Drop Slider Builder...
The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2025-4944 - The LA-Studio Element Kit for Elementor plugin...
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and...
High - CVE-2025-5190 - The Browse As plugin for WordPress is...
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checking in the...