| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit counter added in the fix for GHSA-wgh7-7m3c-fx25. An attacker who can supply untrusted input to Template.Parse can trigger an uncatchable StackOverflowException that immediately terminates the process, even with the default ExpressionDepthLimit enabled. |
| Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. |
| Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. |
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
| COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts datagrams from any sender matching a hardcoded unauthenticated stream ID transmitted in plaintext, attackers can corrupt adjacent stack memory to achieve arbitrary code execution or denial of service. |
| Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes protected only by Vercel edge path rules or split edge middleware. This issue is fixed in 11.0.3. |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. |
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. |
| Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. |
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. |
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. |