| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses. |
| A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service. |
| aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication. |
| Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. |
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. |
| Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. |
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. |
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. |
| Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. |
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
| Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. |
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. |
| Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. |
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. |