Medium - CVE-2024-12610 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and...
Medium - CVE-2024-12611 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due...
Critical - CVE-2024-12876 - The Golo - City Travel Guide WordPress Theme...
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin...
Medium - CVE-2024-13431 - The Appointment Booking Calendar — Simply...
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in...
Medium - CVE-2024-13781 - The Hero Maps Premium plugin for WordPress is...
The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied...
Medium - CVE-2024-13904 - The Platform.ly for WooCommerce plugin for...
The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function. This makes it...
High - CVE-2024-9658 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin...
High - CVE-2025-0959 - The Eventer - WordPress Event & Booking Manager...
The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 due to insufficient...
Critical - CVE-2025-1315 - The InWave Jobs plugin for WordPress is...
The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly validating a...
NA - CVE-2025-21835 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, and the...