| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. |
| A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. |
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. |
| @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route based guard using a non canonical path form that misses the guarded route yet resolves back onto the protected file, disclosing its contents. Applications that protect a subtree of the static root with a route based guard are affected, while applications relying on the allowedPath option are not. This is fixed in @fastify/static 10.1.3, which canonicalizes the pathname, including rejecting backslashes, on the path used for routing and serving. |
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. |
| Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. |
| Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID. |
| Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. |
| Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. |
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue. |
| Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. |
| Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. |
| Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. |
| The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails). |