| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. |
| Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. |
| Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. |
| Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. |
| Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. |
| Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. |
| Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. |
| Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. |
| Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. |
| Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. |
| Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. |
| Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. |
| Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. An attacker can trick a victim into visiting a crafted URL, causing Wallos to exchange the attacker's authorization code and log the victim into the attacker's account. This issue has been patched in version 4.9.4. |
| TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser. |
| A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded. |