Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code …
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing…
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
CWE-306: Missing Authentication for Critical Function
CWE-602: Client-Side Enforcement of Server-Side Security