The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion,...
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before ...
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control...
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before for...
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, o...
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users...
Mattermost Plugins versions
Sales Representative SQL Injection in Groundhogg
Unauthenticated Insecure Direct Object References (IDOR) in GravityView
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.