A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context d…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows…
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows att…
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because t…
Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scen…
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLan…
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI…
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept t…
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.