CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 8.6 | Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2). |
| Exploit 1mo ago | 7.5 | Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the wasip2 descriptor.open-at or wasip1 path_open interfaces by opening a file with only the OpenFlags::TRUNCATE oflag. The root cause is that the clause handling OpenFlags::TRUNCATE in crates/wasi/src/filesystem.rs (Dir::open_at, lines 967–969) did not set open_mode |= OpenMode::WRITE;, which is later used for the access control check against FilePerms to determine whether opening the file is permitted; the single-line fix adds that missing assignment, after which the affected calls correctly fail with error-code.not-permitted and ERRNO_PERM respectively. Only wasmtime-wasi embeddings that combine DirPerms::MUTATE with FilePerms::READ are affected by this bug. In particular, the Wasmtime project's wasmtime-cli's use of wasmtime-wasi is not affected, because it always sets FilePerms::all() for all preopens. This issue has been fixed in versions 24.0.9, 36.0.10 and44.0.2. |
| 1mo ago | 7.5 | Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions. |
| 1mo ago | 6.5 | Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions. |
| 1mo ago | 6.5 | Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions. |
| 1mo ago | 6.5 | Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions. |
| 1mo ago | 8.1 | Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. |
| 1mo ago | 7.1 | Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions. |
| 1mo ago | 7.5 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. |
| 1mo ago | 7.5 | Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. |
| 1mo ago | 7.5 | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. |
| 1mo ago | 8.2 | Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. |
| 1mo ago | 6.5 | Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions. |
| 1mo ago | 6.5 | Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions. |
| 1mo ago | 8.8 | Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. |
| 1mo ago | 6.5 | Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. |
| 1mo ago | 6.5 | Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions. |
| 1mo ago | 5.3 | Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions. |
| 1mo ago | 6.5 | Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions. |
| 1mo ago | 5.9 | Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions. |
| 1mo ago | 6.3 | Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. |
| 1mo ago | 7.2 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions. |
| 1mo ago | 6.5 | Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. |