Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41
Ech0 before 4.4.3 Scope Bypass via profile:read Token
Ech0 before 4.4.3 Authentication Bypass via Comment Panel
Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement
Ech0 before 4.4.3 Missing Authorization via dashboard log endpoints
Ech0 before 4.5.1 Authorization Bypass via Session Tokens
Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass
Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo
Ech0 before 5.0.1 Denial of Service via Accept-Language
ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes
All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise
Uncontrolled memory usage in Innodata Labs’ Poppler JPX decoderUncontrolled memory usage in Innodata Labs’ Poppler JPX decoder
Red Hat Security Advisory: OpenShift Container Platform 4.22.11 packages and security update
hbs vulnerable to XSS via registerAsyncHelper output-escaping bypass
Polkit authentication bypass in LACT
Readabler < 2.0.18 - Unauthenticated SQL Injection
Kalles Addons <= 1.0.6 - Unauthenticated PHP Object Injection
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions
Showing 1 - 20 of 1,000+ results