| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. |
| Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. |
| An unauthenticated user may access restricted repository information under specific conditions. |
| A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.
See vulnerability B-E4 in the related paper below. |
| Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.
See vulnerability B-E3 in the related paper below. |
| An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.
See vulnerability B-E10 in the related paper below. |
| Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. |
| Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider.
This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role. |
| Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. |
| Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. |
| Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. |
| Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. |
| Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events. |