NA - CVE-2024-11045 - A Cross-Site WebSocket Hijacking (CSWSH)...
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The...
NA - CVE-2024-11137 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the...
NA - CVE-2024-11167 - An improper access control vulnerability in...
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs...
NA - CVE-2024-11169 - An unhandled exception in danny-avila/librechat...
An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated...
High - CVE-2024-13558 - The NP Quote Request for WooCommerce plugin for...
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user...
Medium - CVE-2024-13920 - The Order Export & Order Import for WooCommerce...
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it...
High - CVE-2024-13921 - The Order Export & Order Import for WooCommerce...
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from...
Low - CVE-2024-13922 - The Order Export & Order Import for WooCommerce...
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all...
High - CVE-2024-13923 - The Order Export & Order Import for WooCommerce...
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This...
Medium - CVE-2025-1802 - The HT Mega – Absolute Addons For Elementor...
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and...