| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. |
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. |
| Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. |
| Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. |
| Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. |
| HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. |
| HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. |
| Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects New User Approve: from n/a through 3.2.8. |
| Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.
This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142. |
| @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML input with this library exposes full Node.js runtime authority, including environment variable access, filesystem read/write, network access, and subprocess execution, with no safe-mode alternative or opt-out mechanism available. |