The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthent...
An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer wil...
An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a cr...
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by...
Contributor Sensitive Data Exposure in Elementor Website Builder
Contributor Broken Access Control in Slim SEO
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. T...
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by tha...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.