| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. |
| Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fernet key can upload a small, highly compressed zip bomb archive that forces wazuh-clusterd on the master node to decompress the full payload into memory, causing memory exhaustion and service disruption. |
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. |
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. |
| Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. |
| Subscriber Broken Authentication in User Registration <= 5.2.6 versions. |
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. |
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. |
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. |
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. |
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. |