| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS.
This issue affects JetTricks: from n/a through 2.0.1. |
| Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks. |
| Editor SQL Injection in Ultimeter <= 3.0.8 versions. |
| Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions. |
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. |
| Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. |
| Administrator SQL Injection in Email Log <= 2.63 versions. |
| Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. |
| Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions. |
| Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. |
| The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer. |
| JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1. |
| Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. |
| JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1. |