| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. |
| Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. |
| Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. |
| A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
| A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. |
| Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer. |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |
| Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. |
| Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. |
| A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. |