The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.Read More ...
Continue ReadingJuly 10, 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through Read More ...
Continue ReadingJuly 10, 2023
Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin Read More ...
Continue ReadingJuly 10, 2023
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post ( ...
Continue ReadingJuly 10, 2023
Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.Read More ...
Continue ReadingJuly 10, 2023
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.Read More ...
Continue ReadingJuly 10, 2023
Sourcecodester Online Pizza Ordering System v1.0 allows the upload of malicious PHP files resulting in Remote Code Execution (RCE).Read More ...
Continue ReadingJuly 10, 2023
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page.Read More ...
Continue ReadingJuly 10, 2023
Back to Main