βΌ CVE-2022-0253 βΌ
π Read
via "National Vulnerability Database".
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')π Read
via "National Vulnerability Database".
βΌ CVE-2021-24909 βΌ
π Read
via "National Vulnerability Database".
The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issueπ Read
via "National Vulnerability Database".
βΌ CVE-2021-25005 βΌ
π Read
via "National Vulnerability Database".
The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedπ Read
via "National Vulnerability Database".
βΌ CVE-2021-4164 βΌ
π Read
via "National Vulnerability Database".
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)π Read
via "National Vulnerability Database".
βΌ CVE-2021-24838 βΌ
π Read
via "National Vulnerability Database".
The AnyComment WordPress plugin through 0.2.17 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25036 βΌ
π Read
via "National Vulnerability Database".
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldnΓΒ’Γ’β¬ÒβΒ’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0240 βΌ
π Read
via "National Vulnerability Database".
mruby is vulnerable to NULL Pointer Dereferenceπ Read
via "National Vulnerability Database".
βΌ CVE-2021-25037 βΌ
π Read
via "National Vulnerability Database".
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected siteΓ’β¬β’s database (e.g., usernames and hashed passwords).π Read
via "National Vulnerability Database".
βΌ CVE-2021-25046 βΌ
π Read
via "National Vulnerability Database".
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.π Read
via "National Vulnerability Database".
βΌ CVE-2021-3862 βΌ
π Read
via "National Vulnerability Database".
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')π Read
via "National Vulnerability Database".
βΌ CVE-2021-25067 βΌ
π Read
via "National Vulnerability Database".
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25065 βΌ
π Read
via "National Vulnerability Database".
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0256 βΌ
π Read
via "National Vulnerability Database".
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')π Read
via "National Vulnerability Database".
βΌ CVE-2022-0257 βΌ
π Read
via "National Vulnerability Database".
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')π Read
via "National Vulnerability Database".
βΌ CVE-2022-0258 βΌ
π Read
via "National Vulnerability Database".
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Commandπ Read
via "National Vulnerability Database".
ποΈ Celebrations over REvil ransomware arrests in Russia may be premature ποΈ
π Read
via "The Daily Swig".
βItβs not clear whether the developers or lower-level criminals were arrestedβ, threat intel experts tell The Daily Swigπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Celebrations over REvil ransomware arrests in Russia may be premature
βItβs not clear whether the developers or lower-level criminals were arrestedβ, security experts tell The Daily Swig
βΌ CVE-2021-38965 βΌ
π Read
via "National Vulnerability Database".
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33040 βΌ
π Read
via "National Vulnerability Database".
managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22703 βΌ
π Read
via "National Vulnerability Database".
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0245 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44757 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.π Read
via "National Vulnerability Database".