Medium - CVE-2025-2078 - The BlogBuzzTime for WP plugin for WordPress is...
The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and...
Medium - CVE-2025-2205 - The GDPR Cookie Compliance – Cookie Banner,...
The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
NA - CVE-2025-24912 - hostapd fails to process crafted RADIUS packets...
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server...
Medium - CVE-2024-13498 - The NEX-Forms – Ultimate Form Builder – Contact...
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads...
Medium - CVE-2024-12589 - The Finale Lite – Sales Countdown Timer &...
The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the countdown timer in all versions up to, and...
Medium - CVE-2024-13838 - The Uncanny Automator – Easy Automation,...
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2...
NA - CVE-2024-58087 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid...
Medium - CVE-2024-13430 - The Page Builder: Pagelayer – Drag and Drop...
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the...
Critical - CVE-2024-13446 - The Workreap plugin for WordPress is vulnerable...
The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a...
NA - CVE-2024-58088 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The following commit bc235cdb423a ("bpf: Prevent deadlock from recursive...