Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Atta...
Unauthenticated Cross Site Scripting (XSS) in WoodMart
Unauthenticated SQL Injection in Advance Product Search
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms
Unauthenticated SQL Injection in JetEngine
Unauthenticated SQL Injection in JetSmartFilters
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images
Subscriber SQL Injection in Tourfic
Unauthenticated Broken Access Control in MailChimp Block
Unauthenticated SQL Injection in Quotes llama
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.