Show filters
744 Total Results
Displaying 11-20 of 744
Sort by:
Attacker Value
Unknown
CVE-2025-24965
Disclosure Date: February 19, 2025 (last updated February 20, 2025)
crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the target file. The problem is fixed in crun 1.20 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-13365
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2025-1108
Disclosure Date: February 07, 2025 (last updated February 08, 2025)
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.
0
Attacker Value
Unknown
CVE-2025-1107
Disclosure Date: February 07, 2025 (last updated February 08, 2025)
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
0
Attacker Value
Unknown
CVE-2025-25073
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a through 1.
0
Attacker Value
Unknown
CVE-2025-0696
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
0
Attacker Value
Unknown
CVE-2025-0695
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
0
Attacker Value
Unknown
CVE-2025-23510
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Zaantar WordPress Logging Service allows Stored XSS.This issue affects WordPress Logging Service: from n/a through 1.5.4.
0
Attacker Value
Unknown
CVE-2024-11497
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.
0
Attacker Value
Unknown
CVE-2024-11686
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0