| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. |
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. |
| Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. |
| Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. |
| Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |
| Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. |
| HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. |
| HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. |
| HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. |
| HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges. |
| HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. |
| Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects New User Approve: from n/a through 3.2.8. |
| Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities. |