NA - CVE-2025-1798 - The does not sanitise and escape some...
The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.
NA - CVE-2025-27809 - Mbed TLS before 2.28.10 and 3.x before 3.6.3,...
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls...
NA - CVE-2025-27810 - Mbed TLS before 2.28.10 and 3.x before 3.6.3,...
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading...
Medium - CVE-2025-2224 - The Directorist: AI-Powered Business Directory...
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability...
High - CVE-2025-2737 - A vulnerability was found in PHPGurukul Old Age...
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/contactus.php. The manipulation of...
High - CVE-2025-2738 - A vulnerability was found in PHPGurukul Old Age...
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/manage-scdetails.php. The...
High - CVE-2025-2739 - A vulnerability was found in PHPGurukul Old Age...
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-services.php. The...
Medium - CVE-2024-12623 - The DICOM Support plugin for WordPress is...
The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 due to insufficient...
Medium - CVE-2025-1320 - The teachPress plugin for WordPress is...
The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php...
Medium - CVE-2025-2252 - The Easy Digital Downloads – eCommerce Payments...
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via...