SuperStoreFinder – Multiple Vulnerabilities

...Read More ...

Continue Reading
Product Catalog Enquiry for WooCommerce by MultiVendorX < 5.0.6 – Cross-Site Request Forgery via REST API

Description The Product Catalog Enquiry for WooCommerce by MultiVendorX plugin for WordPress is vulnerable to cross-site request forgery due to an improper capability check on the 'catalog_permis ...

Continue Reading
Minder trusts client-provided mapping from repo name to upstream ID

Summary When using a modified client or the grpc interface directly, the RegisterRepository call accepts both the repository owner / repo and the repo_id. Furthermore, these two are not checked for m ...

Continue Reading
CVE-2024-25247

SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude...Read More ...

Continue Reading
Kirby vulnerable to Cross-site scripting (XSS) in the link field “Custom” type

TL;DR This vulnerability affects Kirby sites that use the new link field and output the entered link without additional validation or sanitization. The attack commonly requires user interaction by ano ...

Continue Reading
api-idp-analytic.bsezdx.com Cross Site Scripting vulnerability OBB-3860417

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
Improving Security with Wallarm’s NIST CSF 2.0 Dashboard

Ensuring the security of web applications and APIs is more critical than ever. With threats becoming increasingly prevalent and sophisticated, organizations need to employ comprehensive security measu ...

Continue Reading
CVE-2024-27081

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) al ...

Continue Reading

Back to Main

Subscribe for the latest news: