| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. |
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. |
| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. |
| Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. |
| Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. |
| Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. |
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |
| Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. |
| Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions. |
| Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. |
| Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. |
| Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. |
| aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing. |
| OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown handler before auth middleware executes, causing denial of service to all active AI coding sessions and locking out legitimate remote users regardless of whether UI_PASSWORD is configured. |