| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |
| Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. |
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. |
| Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). |
| Contributor Local File Inclusion in Vino <= 1.9 versions. |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |
| Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. |
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). |
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. |
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. |
| Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12. |