Latest CVE Feed
-
9.8
CRITICALCVE-2022-0781
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection... Read more
Affected Products : nirweb_support- EPSS Score: %81.28
- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0748
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.... Read more
Affected Products : post-loader- EPSS Score: %1.14
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0760
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an una... Read more
Affected Products : simple_link_directory- EPSS Score: %77.44
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0769
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and aut... Read more
Affected Products : users_ultra- EPSS Score: %78.50
- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0827
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users... Read more
Affected Products : bestbooks- EPSS Score: %68.78
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0749
This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restricti... Read more
Affected Products : singoocms.utility- EPSS Score: %0.47
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.... Read more
- EPSS Score: %0.31
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0658
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthentica... Read more
Affected Products : commonsbooking- EPSS Score: %44.43
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0631
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- EPSS Score: %0.27
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0570
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- EPSS Score: %0.27
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0592
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.... Read more
Affected Products : mapsvg- EPSS Score: %69.83
- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0675
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe ... Read more
Affected Products : firewall- EPSS Score: %0.28
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0441
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin... Read more
Affected Products : masterstudy_lms- EPSS Score: %79.87
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.24
- Published: Jan. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0362
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.... Read more
Affected Products : showdoc- EPSS Score: %0.27
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.20
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0349
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection... Read more
Affected Products : notificationx- EPSS Score: %61.49
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0254
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection... Read more
Affected Products : zero-spam- EPSS Score: %0.88
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0169
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users)... Read more
Affected Products : photo_gallery- EPSS Score: %81.69
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0223
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthe... Read more
Affected Products : ecostruxure_power_commission- EPSS Score: %0.23
- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024