Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Command Injection in @oblique/cli
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header...
wp-downloadmanager: Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal
In Eclipse Theia versions 1
In Eclipse Theia versions 0
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1
Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
Potential information leakage from manager /network/graph API in NeuVector
Denial-of-service vulnerability in M-Files Server
Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String
Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and beco...
Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceac...
JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter
WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Injection
Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter
User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection
TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference
Showing 1 - 20 of 1,000+ results