Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 all…
Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be…
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java comp…
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce…
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on …
An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecu…
libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in …
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the…
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted f…
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentiall…
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK o…
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3…
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red…
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-sup…
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in…
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura…
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r…
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx …
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.