Medium - CVE-2025-1769 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the...
Low - CVE-2025-1911 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the...
High - CVE-2025-1912 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the...
High - CVE-2025-1913 - The Product Import Export for WooCommerce –...
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via...
High - CVE-2025-2110 - The WP Compress – Instant Performance & Speed...
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its...
Medium - CVE-2025-2228 - The Responsive Addons for Elementor – Free...
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
Medium - CVE-2022-39163 - IBM Cognos Controller 11.0.0 through 11.1.0 is...
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further...
NA - CVE-2024-45351 - A code execution vulnerability exists in the...
A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious...
NA - CVE-2025-23203 - Icinga Director is an Icinga config deployment...
Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.3 and 1.11.3 on several director endpoints of REST API. To...
NA - CVE-2025-24808 - Discourse is an open-source discussion...
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group...