CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1h ago | 6.5 | AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs. |
| Exploit 1h ago | 5.9 | Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access. |
| Exploit 1h ago | 9.1 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13. |
| Exploit 1h ago | 9.1 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13. |
| Exploit 1h ago | 6.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1. |
| Exploit 1h ago | 6.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0. |
| Exploit 1h ago | 7.4 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer. When the retry or buffering middleware reads the body before the reverse proxy clones the request, the attacker-controlled trailer value reaches a backend that merges trailers into the header namespace, bypassing the documented delete or reject behavior and potentially spoofing identity or forwarded routing data. This issue is fixed in 3.7.13. |
| 1h ago | 6.5 | import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. |
| 1h ago | 8.1 | Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. |
| 1h ago | 7.5 | Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. |
| Exploit 1h ago | 7.5 | Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. |
| 1h ago | 8.1 | Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. |
| 1h ago | 9.3 | Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. |
| 1h ago | 7.3 | Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. |
| 1h ago | 6.5 | Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. |
| 1h ago | 6.5 | Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. |
| 1h ago | 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. |
| 1h ago | 6.3 | Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. |
| 1h ago | 6.5 | Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. |
| 1h ago | 6.5 | Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. |
| 1h ago | 8.1 | Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions. |
| 1h ago | 7.1 | Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. |
| 1h ago | 6.5 | Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. |