| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. |
| Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions. |
| Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. |
| Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. |
| Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. |
| Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. |
| Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. |
| Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. |
| Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. |
| Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. |
| Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. |
| Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. |
| Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. |
| The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot). |
| Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. |
| Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. |
| Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. |
| thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping. |
| An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. |