A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipula...
A weakness has been identified in langflow-ai langflow up to 1.10.2. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.py of the component LambdaFilterComponent. Executing a manipulation can ...
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and in...
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is ...
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and...