| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. |
| Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. |
| Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. |
| Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. |
| Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. |
| Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. |
| Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. |
| Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. |
| The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot). |
| Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. |
| Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. |
| Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. |
| thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping. |
| An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. |
| A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device. |
| TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. |
| Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. |
| Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery.
This issue affects Skyline WP: from n/a through 1.0.10. |
| Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition. |