Show filters
468 Total Results
Displaying 11-20 of 468
Sort by:
Attacker Value
Unknown
CVE-2025-0493
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included
0
Attacker Value
Unknown
CVE-2025-0142
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access.
0
Attacker Value
Unknown
CVE-2025-21107
Disclosure Date: January 30, 2025 (last updated February 08, 2025)
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
0
Attacker Value
Unknown
CVE-2025-24600
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Missing Authorization vulnerability in David F. Carr RSVPMarker . This issue affects RSVPMarker : from n/a through 11.4.5.
0
Attacker Value
Unknown
CVE-2025-24706
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Stored XSS. This issue affects WC Marketplace: from n/a through 4.2.13.
0
Attacker Value
Unknown
CVE-2024-13519
Disclosure Date: January 18, 2025 (last updated January 18, 2025)
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.9.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2025-23930
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Missing Authorization vulnerability in iTechArt-Group PayPal Marketing Solutions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through 1.2.
0
Attacker Value
Unknown
CVE-2024-12226
Disclosure Date: January 16, 2025 (last updated January 16, 2025)
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.
0
Attacker Value
Unknown
CVE-2025-0394
Disclosure Date: January 14, 2025 (last updated January 14, 2025)
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2025-21380
Disclosure Date: January 09, 2025 (last updated February 06, 2025)
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
0