| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. |
| Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. |
| Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions. |
| Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. |
| Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. |
| Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. |
| Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. |
| Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. |
| Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. |
| Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. |
| Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. |
| Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. |
| Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. |
| Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. |
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |
| Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user's workflow, and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, and the attacker can set tool inputs and read outputs (potentially including data from the owner's connected integrations), breaking user and project isolation. |
| An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace. |
| Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript. |