| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. |
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. |
| Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. |
| Contributor Local File Inclusion in Vino <= 1.9 versions. |
| Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
| Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. |
| Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. |
| CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and passed directly to `new unsigned char[header_size]` without being bounded against the actual file size. A value up to ~4 GB is accepted. If the subsequent `fread` returns `short` as it will for any malformed file), the function throws a `CImgIOException` and the allocated buffer is never freed. A 6-byte crafted file is sufficient to trigger an allocation of ~1.3 GB per call, with the full allocation leaked on every error path. The issue is reachable via `load_analyze()` and the generic `load()` when the file extension is .hdr, .img, or .nii. Version 4.0.0 fixes the issue. |
| The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data. |
| The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build. |
| The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login. |
| RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation |
| Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. |