Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPE…
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates …
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Acce…
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update …
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). …
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functi…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite …
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Private Repository Metadata Remains Accessible After Access Revocation
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Cross-repository issue/comment attachment re-linking can expose private attachment content
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions.
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= …
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.