| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. |
| When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.
A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access. |
| Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. |
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. |
| Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. |
| Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. |
| Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is fixed in 4.5.1. |
| Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. |
| Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.
This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. |
| A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. |
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. |
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. |
| Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. |
| Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. |
| Unauthenticated PHP Object Injection in Agora <= 1.9 versions. |