NA - CVE-2025-0652 - An issue has been discovered in GitLab EE/CE...
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2...
NA - CVE-2025-1257 - An issue was discovered in GitLab EE affecting...
An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow...
NA - CVE-2025-1401 - The WP Click Info WordPress plugin through...
The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2025-1436 - The Limit Bio WordPress plugin through 1.0 does...
The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin...
NA - CVE-2025-1486 - The WoWPth WordPress plugin through 2.0 does...
The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high...
NA - CVE-2025-1487 - The WoWPth WordPress plugin through 2.0 does...
The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high...
High - CVE-2025-1119 - The Appointment Booking Calendar — Simply...
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5....
NA - CVE-2025-2271 - A vulnerability exists in Issuetrak v17.2.2 and...
A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability...
Medium - CVE-2025-1785 - The Download Manager plugin for WordPress is...
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for...
High - CVE-2025-25175 - A vulnerability has been identified in...
A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption...