| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-75574 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2026 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in… | ||
| CVE-2026-72702 | Med | 0.28 | 5.4 | 0.00 | Aug 25, 2026 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who… | ||
| CVE-2026-72701 | Low | 0.17 | 3.7 | 0.00 | Aug 25, 2026 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values… | ||
| CVE-2026-72700 | Hig | 0.49 | 7.5 | 0.00 | Aug 25, 2026 | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler).… | ||
| CVE-2026-72699 | Med | 0.27 | 5.3 | 0.00 | Aug 25, 2026 | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while… | ||
| CVE-2026-72698 | Med | 0.35 | 6.5 | 0.00 | Aug 25, 2026 | Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like… | ||
| CVE-2026-72697 | Med | 0.35 | 6.5 | 0.00 | Aug 25, 2026 | Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply… | ||
| CVE-2026-72696 | Hig | 0.48 | 8.4 | 0.00 | Aug 25, 2026 | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a… | ||
| CVE-2026-72695 | Hig | 0.46 | 8.1 | 0.01 | Aug 25, 2026 | Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the… | ||
| CVE-2026-56710 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from… | ||
| CVE-2026-56709 | Hig | 0.49 | 7.5 | 0.00 | Aug 25, 2026 | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the… | ||
| CVE-2026-56708 | Med | 0.27 | 5.3 | 0.00 | Aug 25, 2026 | Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups… | ||
| CVE-2026-56707 | Hig | 0.43 | 7.7 | 0.00 | Aug 25, 2026 | Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in… | ||
| CVE-2026-56706 | Med | 0.37 | 6.8 | 0.00 | Aug 25, 2026 | Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the… | ||
| CVE-2026-56705 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote… | ||
| CVE-2026-56704 | Med | 0.33 | 6.1 | 0.00 | Aug 25, 2026 | Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary… | ||
| CVE-2026-56703 | Hig | 0.40 | 7.2 | 0.01 | Aug 25, 2026 | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server. | ||
| CVE-2026-56702 | Hig | 0.50 | 8.8 | 0.01 | Aug 25, 2026 | Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in… | ||
| CVE-2026-34968 | Hig | 0.46 | 8.1 | 0.01 | Aug 25, 2026 | Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any… | ||
| CVE-2026-34967 | Med | 0.28 | 5.4 | 0.00 | Aug 25, 2026 | Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with… | ||
| CVE-2026-34964 | Med | 0.31 | 5.8 | 0.00 | Aug 25, 2026 | Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port=… | ||
| CVE-2026-34959 | Med | 0.31 | 4.7 | 0.00 | Aug 25, 2026 | Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into… | ||
| CVE-2026-19801 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2026 | The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to… | ||
| CVE-2026-16434 | Low | 0.08 | — | 0.00 | Aug 25, 2026 | Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com… | ||
| CVE-2026-15023 | Med | 0.42 | 6.5 | 0.01 | Aug 25, 2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied… | ||
| CVE-2026-10630 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2026 | The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a… | ||
| CVE-2026-66766 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2026 | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful… | ||
| CVE-2026-59183 | Med | 0.29 | 5.5 | 0.00 | Aug 25, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can… | ||
| CVE-2026-55373 | Med | 0.33 | 6.2 | 0.00 | Aug 25, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a… | ||
| CVE-2026-55371 | Med | 0.38 | — | 0.00 | Aug 25, 2026 | OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exr_attr_set_bytes(). The public… | ||
| CVE-2026-55059 | Med | 0.33 | 6.1 | 0.00 | Aug 25, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int… | ||
| CVE-2026-54920 | Non | 0.00 | 0.0 | 0.00 | Aug 25, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an… | ||
| CVE-2026-53532 | Hig | 0.39 | — | 0.00 | Aug 24, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls… | ||
| CVE-2026-78435 | Low | 0.25 | 3.8 | 0.01 | Aug 24, 2026 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be… | ||
| CVE-2026-78434 | Med | 0.42 | 6.5 | 0.01 | Aug 24, 2026 | A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The… | ||
| CVE-2026-78284 | Hig | 0.49 | 8.6 | 0.01 | Aug 24, 2026 | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | ||
| CVE-2026-78282 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | ||
| CVE-2026-78268 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | ||
| CVE-2026-78267 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||
| CVE-2026-78266 | Med | 0.42 | 6.5 | 0.00 | Aug 24, 2026 | Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. | ||
| CVE-2026-78265 | Cri | 0.57 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | ||
| CVE-2026-78264 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | ||
| CVE-2026-78263 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | ||
| CVE-2026-78262 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||
| CVE-2026-78259 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | ||
| CVE-2026-77384 | Hig | 0.42 | 7.5 | 0.01 | Aug 24, 2026 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer… | ||
| CVE-2026-77337 | Cri | 0.52 | — | 0.01 | Aug 24, 2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when… | ||
| CVE-2026-68516 | Med | 0.35 | 6.5 | 0.00 | Aug 24, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ… | ||
| CVE-2026-45404 | Med | 0.31 | — | 0.00 | Aug 24, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent… | ||
| CVE-2026-32563 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. |
- risk 0.57cvss 8.8epss 0.01
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in…
- risk 0.28cvss 5.4epss 0.00
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who…
- risk 0.17cvss 3.7epss 0.00
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values…
- risk 0.49cvss 7.5epss 0.00
The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler).…
- risk 0.27cvss 5.3epss 0.00
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while…
- risk 0.35cvss 6.5epss 0.00
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like…
- risk 0.35cvss 6.5epss 0.00
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply…
- risk 0.48cvss 8.4epss 0.00
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a…
- risk 0.46cvss 8.1epss 0.01
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the…
- risk 0.57cvss 9.8epss 0.01
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from…
- risk 0.49cvss 7.5epss 0.00
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the…
- risk 0.27cvss 5.3epss 0.00
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups…
- risk 0.43cvss 7.7epss 0.00
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in…
- risk 0.37cvss 6.8epss 0.00
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the…
- risk 0.57cvss 9.8epss 0.01
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote…
- risk 0.33cvss 6.1epss 0.00
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary…
- risk 0.40cvss 7.2epss 0.01
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.
- risk 0.50cvss 8.8epss 0.01
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in…
- risk 0.46cvss 8.1epss 0.01
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any…
- risk 0.28cvss 5.4epss 0.00
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with…
- risk 0.31cvss 5.8epss 0.00
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port=…
- risk 0.31cvss 4.7epss 0.00
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into…
- risk 0.28cvss 4.3epss 0.00
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to…
- risk 0.08cvss —epss 0.00
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com…
- risk 0.42cvss 6.5epss 0.01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied…
- risk 0.28cvss 4.3epss 0.00
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a…
- risk 0.49cvss 7.5epss 0.01
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful…
- risk 0.29cvss 5.5epss 0.00
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can…
- risk 0.33cvss 6.2epss 0.00
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a…
- risk 0.38cvss —epss 0.00
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exr_attr_set_bytes(). The public…
- risk 0.33cvss 6.1epss 0.00
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int…
- risk 0.00cvss 0.0epss 0.00
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an…
- risk 0.39cvss —epss 0.00
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls…
- risk 0.25cvss 3.8epss 0.01
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be…
- risk 0.42cvss 6.5epss 0.01
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The…
- risk 0.49cvss 8.6epss 0.01
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
- risk 0.57cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- risk 0.47cvss 7.3epss 0.00
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
- risk 0.42cvss 7.5epss 0.01
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer…
- risk 0.52cvss —epss 0.01
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when…
- risk 0.35cvss 6.5epss 0.00
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ…
- risk 0.31cvss —epss 0.00
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent…
- risk 0.64cvss 9.8epss 0.01
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.