Latest CVEs

CVE-2024-55895 - IBM InfoSphere Information Server Information Disclosure Vulnerability
Published: Sat, 29 Mar 2025 13:15:40 +0000
CVE ID : CVE-2024-55895
Published : March 29, 2025, 1:15 p.m. | 2 hours, 24 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2024-11180 - "ElementsKit Elementor Addons WordPress Stored Cross-Site Scripting Vulnerability"
Published: Sat, 29 Mar 2025 08:15:13 +0000
CVE ID : CVE-2024-11180
Published : March 29, 2025, 8:15 a.m. | 7 hours, 25 minutes ago
Description : The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2840 - WordPress DAP to Autoresponders Email Syncing Sensitive Information Exposure
Published: Sat, 29 Mar 2025 07:15:19 +0000
CVE ID : CVE-2025-2840
Published : March 29, 2025, 7:15 a.m. | 8 hours, 25 minutes ago
Description : The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2803 - WordPress So-Called Air Quotes Plugin Shortcode Injection Vulnerability
Published: Sat, 29 Mar 2025 07:15:18 +0000
CVE ID : CVE-2025-2803
Published : March 29, 2025, 7:15 a.m. | 8 hours, 25 minutes ago
Description : The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2266 - WooCommerce Checkout Mestres do WP Privilege Escalation Vulnerability
Published: Sat, 29 Mar 2025 07:15:18 +0000
CVE ID : CVE-2025-2266
Published : March 29, 2025, 7:15 a.m. | 8 hours, 25 minutes ago
Description : The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2249 - "WordPress SoJ SoundSlides Arbitrary File Upload Vulnerability"
Published: Sat, 29 Mar 2025 07:15:17 +0000
CVE ID : CVE-2025-2249
Published : March 29, 2025, 7:15 a.m. | 8 hours, 25 minutes ago
Description : The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2006 - "BBPress Inline Image Upload Arbitrary File Upload Vulnerability"
Published: Sat, 29 Mar 2025 07:15:17 +0000
CVE ID : CVE-2025-2006
Published : March 29, 2025, 7:15 a.m. | 8 hours, 25 minutes ago
Description : The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This may be exploitable by unauthenticated attackers when the "Allow guest users without accounts to create topics and replies" setting is enabled.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2024-13557 - United Themes WordPress Shortcodes Arbitrary Execution Vulnerability
Published: Sat, 29 Mar 2025 07:15:12 +0000
CVE ID : CVE-2024-13557
Published : March 29, 2025, 7:15 a.m. | 8 hours, 25 minutes ago
Description : The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-1217 - Apache HTTP Server HTTP Response Header Parsing Vulnerability
Published: Sat, 29 Mar 2025 06:15:36 +0000
CVE ID : CVE-2025-1217
Published : March 29, 2025, 6:15 a.m. | 9 hours, 24 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31374 - Apache HTTP Server Cross-Site Request Forgery
Published: Sat, 29 Mar 2025 04:15:39 +0000
CVE ID : CVE-2025-31374
Published : March 29, 2025, 4:15 a.m. | 11 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31373 - Apache HTTP Server Cross-Site Request Forgery
Published: Sat, 29 Mar 2025 04:15:39 +0000
CVE ID : CVE-2025-31373
Published : March 29, 2025, 4:15 a.m. | 11 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31372 - Cisco Webex Meeting Server Unvalidated Redirect
Published: Sat, 29 Mar 2025 04:15:38 +0000
CVE ID : CVE-2025-31372
Published : March 29, 2025, 4:15 a.m. | 11 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31371 - Apache HTTP Server Command Injection
Published: Sat, 29 Mar 2025 04:15:38 +0000
CVE ID : CVE-2025-31371
Published : March 29, 2025, 4:15 a.m. | 11 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31370 - Apache HTTP Server Denial of Service
Published: Sat, 29 Mar 2025 04:15:38 +0000
CVE ID : CVE-2025-31370
Published : March 29, 2025, 4:15 a.m. | 11 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31369 - Apache HTTP Server Cross-Site Request Forgery
Published: Sat, 29 Mar 2025 04:15:38 +0000
CVE ID : CVE-2025-31369
Published : March 29, 2025, 4:15 a.m. | 11 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31368 - Apache HTTP Server Command Injection
Published: Sat, 29 Mar 2025 04:15:29 +0000
CVE ID : CVE-2025-31368
Published : March 29, 2025, 4:15 a.m. | 11 hours, 25 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-31367 - Apache HTTP Server Cross-Site Request Forgery
Published: Sat, 29 Mar 2025 04:15:24 +0000
CVE ID : CVE-2025-31367
Published : March 29, 2025, 4:15 a.m. | 11 hours, 25 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2024-7577 - IBM InfoSphere Information Server Credentials Disclosure Vulnerability
Published: Sat, 29 Mar 2025 00:15:24 +0000
CVE ID : CVE-2024-7577
Published : March 29, 2025, 12:15 a.m. | 15 hours, 25 minutes ago
Description : IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2024-51477 - IBM InfoSphere Information Server Information Disclosure Vulnerability
Published: Sat, 29 Mar 2025 00:15:23 +0000
CVE ID : CVE-2024-51477
Published : March 29, 2025, 12:15 a.m. | 15 hours, 25 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2024-43186 - IBM InfoSphere Information Server Local File Disclosure
Published: Sat, 29 Mar 2025 00:15:23 +0000
CVE ID : CVE-2024-43186
Published : March 29, 2025, 12:15 a.m. | 15 hours, 25 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2782 - WatchGuard Terminal Services Agent Directory Permissions Escalation
Published: Fri, 28 Mar 2025 23:15:18 +0000
CVE ID : CVE-2025-2782
Published : March 28, 2025, 11:15 p.m. | 16 hours, 25 minutes ago
Description : The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Terminal Services Agent: from 12.0 through 12.10.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-2781 - WatchGuard Mobile VPN with SSL Client Directory Permission Escalation Vulnerability
Published: Fri, 28 Mar 2025 23:15:18 +0000
CVE ID : CVE-2025-2781
Published : March 28, 2025, 11:15 p.m. | 16 hours, 25 minutes ago
Description : The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Mobile VPN with SSL Client: from 11.0 through 12.11.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-28097 - OneNav HTTP Header XSS
Published: Fri, 28 Mar 2025 22:15:18 +0000
CVE ID : CVE-2025-28097
Published : March 28, 2025, 10:15 p.m. | 17 hours, 25 minutes ago
Description : OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-28096 - OneNav SSRF Vulnerability
Published: Fri, 28 Mar 2025 22:15:18 +0000
CVE ID : CVE-2025-28096
Published : March 28, 2025, 10:15 p.m. | 17 hours, 25 minutes ago
Description : OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE-2025-28094 - Shopxo SSRF and XSS Vulnerabilities
Published: Fri, 28 Mar 2025 22:15:18 +0000
CVE ID : CVE-2025-28094
Published : March 28, 2025, 10:15 p.m. | 17 hours, 25 minutes ago
Description : shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...