| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. |
| An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. |
| A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure. |
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. |
| Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. |
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. |
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. |
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. |
| Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. |
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. |
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. |
| Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. |
| Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. |
| Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. |
| Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. |