| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. |
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
| COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts datagrams from any sender matching a hardcoded unauthenticated stream ID transmitted in plaintext, attackers can corrupt adjacent stack memory to achieve arbitrary code execution or denial of service. |
| Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes protected only by Vercel edge path rules or split edge middleware. This issue is fixed in 11.0.3. |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. |
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. |
| Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. |
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. |
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. |
| Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials. |
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. |