CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 3h ago | 5.4 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services. |
| Exploit 3h ago | 8.4 | amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names. |
| 3h ago | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. |
| 3h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. |
| 3h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. |
| 3h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. |
| 3h ago | 6.5 | Subscriber Broken Access Control in Motors <= 1.4.113 versions. |
| 3h ago | 9.8 | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. |
| 3h ago | 6.3 | Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. |
| 3h ago | 6.5 | Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. |
| 3h ago | 7.7 | Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. |
| 3h ago | 6.5 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. |
| 3h ago | 8.5 | Subscriber SQL Injection in Reviewer <= 3.14.2 versions. |
| 3h ago | 8.1 | Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. |
| 3h ago | 8.1 | Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. |
| 3h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. |
| 3h ago | 6 | Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. |
| 3h ago | 8.1 | Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. |
| 3h ago | 9.3 | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. |
| 3h ago | 9.3 | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. |
| 3h ago | 6.5 | Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. |
| 3h ago | 7.5 | Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. |
| 3h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. |
| 3h ago | 6.5 | Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. |
| 3h ago | 7.5 | Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. |
| 3h ago | 9.8 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. |
| 3h ago | 6.5 | Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. |
| 3h ago | 7.5 | Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. |
| 3h ago | 7.5 | Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. |
| 3h ago | 7.5 | Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. |