| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. |
| Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. |
| Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. |
| Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. |
| Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. |
| Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. |
| Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. |
| Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. |
| Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account. |
| OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks. |
| Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks. |
| Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem. |
| CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control |
| CWE-602: Client-Side Enforcement of Server-Side Security |
| CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor |
| CWE-203: Observable Discrepancy |
| CWE-284: Improper Access Control |
| CWE-287: Improper Authentication |