Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed in AlanWeb SCADA version 9.8.5
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).