| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) |
| Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense). |
| Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. |
| Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19. |
| Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. |
| Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. |
| Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. |
| Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. |
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. |
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. |
| Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. |
| Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. |
| Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. |
| Unauthenticated Broken Access Control in Bookly <= 28.2 versions. |
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. |
| Subscriber Broken Access Control in FormGent <= 1.12.2 versions. |
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. |
| SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces. A renderer connected to an attacker-controlled remote kernel can therefore send {cmd: "lockscreenByMode"} and have it delivered across the workspace boundary; a sibling workspace window whose lockScreenMode is set to 1 invokes lockScreen(). Repeated messages allow the remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. No confidentiality, integrity, or code-execution impact was observed. |