Snapshot Sources Records CVE explorer ATT&CK explorer Exact snapshot results
353,537 CVE records CVE ID descending · no relevance ranking Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts.
To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.
PUBLISHED
Vendor AWS
Product AWS Encryption SDK for Python
Provider severity MEDIUM
Conflicts 1 Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
PUBLISHED
Vendor Pepro Dev. Group
Product PeproDev Ultimate Invoice
Provider severity MEDIUM
Conflicts 0 Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
PUBLISHED
Vendor Complianz
Product Complianz
Provider severity MEDIUM
Conflicts 0 Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
PUBLISHED
Vendor Complianz
Product Complianz
Provider severity HIGH
Conflicts 0 Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
PUBLISHED
Vendor Complianz
Product Complianz
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
PUBLISHED
Vendor Dokan Multivendor Plugin
Product Dokan Pro
Provider severity HIGH
Conflicts 0 Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
PUBLISHED
Vendor Dokan
Product Dokan Pro
Provider severity HIGH
Conflicts 0 Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
PUBLISHED
Vendor Dokan
Product Dokan Pro
Provider severity HIGH
Conflicts 0 Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
PUBLISHED
Vendor Dokan WordPress Plugin
Product Dokan Pro
Provider severity HIGH
Conflicts 0 Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
PUBLISHED
Vendor Jonathan Daggerhart
Product Query Wrangler
Provider severity MEDIUM
Conflicts 0 Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
PUBLISHED
Vendor mischiefmarmot
Product Create by Mediavine
Provider severity MEDIUM
Conflicts 0 The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user
PUBLISHED
Vendor goback2
Product Logo Manager For Enamad
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
PUBLISHED
Vendor LA-Studio
Product LA-Studio Element Kit for Elementor
Provider severity MEDIUM
Conflicts 0 Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
PUBLISHED
Vendor LA-Studio
Product LA-Studio Element Kit for Elementor
Provider severity HIGH
Conflicts 0 Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
PUBLISHED
Vendor ThemeGoods
Product Photography
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
PUBLISHED
Vendor Bastien Ho
Product Event post
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
PUBLISHED
Vendor Daniel Iser
Product Content Control
Provider severity MEDIUM
Conflicts 0 Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
PUBLISHED
Vendor AnalogWP
Product Style Kits
Provider severity MEDIUM
Conflicts 0 Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
PUBLISHED
Vendor hashthemes
Product HashThemes Demo Importer
Provider severity MEDIUM
Conflicts 0 Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
PUBLISHED
Vendor LA-Studio
Product LA-Studio Element Kit for Elementor
Provider severity MEDIUM
Conflicts 0 Contributor Local File Inclusion in Vino <= 1.9 versions.
PUBLISHED
Vendor Elated-Themes
Product Vino
Provider severity HIGH
Conflicts 0 Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.
PUBLISHED
Vendor CodexThemes
Product TheGem
Provider severity MEDIUM
Conflicts 0 Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
PUBLISHED
Vendor MVP Themes
Product Reviewer
Provider severity MEDIUM
Conflicts 0 Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
PUBLISHED
Vendor CridioStudio
Product ListingPro
Provider severity MEDIUM
Conflicts 0 Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
PUBLISHED
Vendor Select-Themes
Product Tonda Core
Provider severity HIGH
Conflicts 0 Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
PUBLISHED
Vendor uxper
Product Civi
Provider severity MEDIUM
Conflicts 0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
PUBLISHED
Vendor WP Chill
Product Modula Image Gallery
Provider severity MEDIUM
Conflicts 0 Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
PUBLISHED
Vendor WPManageNinja
Product Ninja Tables
Provider severity MEDIUM
Conflicts 0 Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
PUBLISHED
Vendor Nexcess
Product Virtue/Ascend/Pinnacle Toolkit
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
PUBLISHED
Vendor Kit
Product Kit (formerly ConvertKit)
Provider severity MEDIUM
Conflicts 0 Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
PUBLISHED
Vendor Avada Studio
Product Avada Core
Provider severity CRITICAL
Conflicts 0 Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
PUBLISHED
Vendor WPManageNinja
Product Fluent Support
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
PUBLISHED
Vendor Strategy11 Team
Product AWP Classifieds
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
PUBLISHED
Vendor Crocoblock. Jetimpex Inc.
Product JetBooking
Provider severity MEDIUM
Conflicts 0 Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
PUBLISHED
Vendor Crocoblock. Jetimpex Inc.
Product JetEngine
Provider severity MEDIUM
Conflicts 0 Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
PUBLISHED
Vendor Crocoblock. Jetimpex Inc.
Product JetBooking
Provider severity MEDIUM
Conflicts 0 Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
PUBLISHED
Vendor Crocoblock. Jetimpex Inc.
Product JetElements For Elementor
Provider severity MEDIUM
Conflicts 0 Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
PUBLISHED
Vendor Nexcess
Product GiveWP
Provider severity MEDIUM
Conflicts 0 Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
PUBLISHED
Vendor masteriyo
Product Masteriyo - LMS
Provider severity MEDIUM
Conflicts 0 Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
PUBLISHED
Vendor Uncanny Owl
Product Uncanny Automator
Provider severity HIGH
Conflicts 0 Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
PUBLISHED
Vendor Webの相談所
Product Really Simple CSV Importer
Provider severity CRITICAL
Conflicts 0 Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
PUBLISHED
Vendor zarinpal
Product Zarinpal Gateway
Provider severity MEDIUM
Conflicts 0 Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
PUBLISHED
Vendor Chouby
Product Polylang
Provider severity MEDIUM
Conflicts 0 Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
PUBLISHED
Vendor yoomoney
Product ЮKassa для WooCommerce
Provider severity MEDIUM
Conflicts 0 Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
PUBLISHED
Vendor PickPlugins
Product Product Slider for WooCommerce
Provider severity MEDIUM
Conflicts 0 Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
PUBLISHED
Vendor MapSVG
Product MapSVG
Provider severity CRITICAL
Conflicts 0 Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
PUBLISHED
Vendor ExpressTech Systems
Product Quiz And Survey Master
Provider severity HIGH
Conflicts 0 Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
PUBLISHED
Vendor motov.net
Product Ebook Store
Provider severity MEDIUM
Conflicts 0 Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
PUBLISHED
Vendor motov.net
Product Ebook Store
Provider severity MEDIUM
Conflicts 0 Contributor SQL Injection in MapSVG <= 8.14.0 versions.
PUBLISHED
Vendor RomanCode
Product MapSVG
Provider severity HIGH
Conflicts 0