| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an application that links the library may cause that application to terminate unexpectedly, resulting in denial of service. |
| A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS.
This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. |
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. |
| Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. |
| An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected. |
| Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. |
| Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. |
| Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. |
| Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. |
| Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. |
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. |
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. |
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. |
| Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. |