| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request. |
| Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1. |
| Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. |
| Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. |
| Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. |
| Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. |
| Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. |
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. |
| Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. |
| Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing. |
| An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification. |
| Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. |
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. |
| Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. |