| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys. |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS.
This issue affects FileOrbis: before 16.5. |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal.
This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22. |
| Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data.
This issue affects Cryptosim: before 3.1.0.229. |
| Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects EdoWEB: before 780-g7. |
| BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available. |
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. |
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
| Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. |
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. |
| Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. |
| Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. |
| Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. |
| Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. |