In WordPress File Upload plugin versions up to 4.24.12 a critical severity vulnerability CVE-2024-11635 was detected. This vulnerability allows unauthenticated attackers to execute remote code via the ‘wfu_ABSPATH’ cookie parameter. To address this issue, users must upgrade to WordPress File Upload plugin version 4.24.14 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11635.
Read more CMSIn WordPress Header Builder Plugin – Pearl versions up to 1.3.8 a medium severity vulnerability CVE-2024-12206 was detected. It allows attackers to delete headers by tricking admins into clicking malicious links. To address this issue, users should upgrade to version 1.3.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12206.
Read more CMSIn Nextcloud Server and Enterprise Server versions from 22.0.0 to 24.0.6 a medium severity vulnerability was detected. This vulnerability allows shared items to remain accessible to users after they are removed from a group, even when the server is configured to restrict sharing within groups. To address this issue, users should upgrade to Nextcloud Server versions 22.2.11, 23.0.11, or 24.0.6, and Nextcloud Enterprise Server versions 22.2.11, 23.0.11, or 24.0.6. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52516.
Read more StorageIn OpenVPN versions prior to 2.6.11 a critical severity vulnerability CVE-2024-5594 was detected. This vulnerability allows attackers to exploit improperly sanitized PUSH_REPLY messages, potentially injecting arbitrary data into third-party executables or plug-ins. To address this issue, users should upgrade to OpenVPN version 2.6.11 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5594.
Read more SecurityIn Invoice Ninja versions before 5.10.43 a high severity vulnerability CVE-2024-55555 was detected. This vulnerability allows attackers with access to the APP_KEY to execute remote code without authentication. The issue arises from insecure handling of serialized objects in a pre-authenticated route. To address this issue, users must upgrade to Invoice Ninja version 5.10.43 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-55555.
Read more SecurityIn GitLab EE versions 18.5 before 18.5.5, 18.6 before 18.6.3 and 18.7 before 18.7.1 a medium severity vulnerability CVE-2025-13781 was detected. This vulnerability allows an authenticated attacker to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations. To address this issue, users should upgrade GitLab EE to versions 18.5.5, 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13781.
Read more Developer ToolsIn Redis versions from 7.0.0 to prior to 7.2.7 and from 7.4.0 to prior to 7.4.2 a medium severity vulnerability CVE-2024-51741 was detected. This vulnerability allows an authenticated user with sufficient privileges to create a malformed ACL selector, which, when accessed, triggers a server panic and subsequent denial of service. To address this issue, users should upgrade to Redis version 7.2.7 or 7.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-51741.
Read more DatabaseIn GitLab CE/EE versions 18.6 before 18.6.3 and 18.7 before 18.7.1 a high severity vulnerability CVE-2025-13761 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary code in the context of an authenticated user’s browser by exploiting improper input neutralization and convincing a user to visit a specially crafted webpage. To address this issue, users should upgrade GitLab CE/EE to versions 18.6.3, 18.7.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13761.
Read more Developer ToolsIn Redis versions before 7.4.2, 7.2.7 and 6.2.17 a high severity vulnerability CVE-2024-46981 was detected. This vulnerability allows authenticated users to execute remote code by using a specially crafted Lua script to manipulate the garbage collector. To address this issue, users must upgrade to Redis version 7.4.2, 7.2.7 or 6.2.17. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-46981.
Read more Database