‼ CVE-2022-1250 ‼
📖 Read
via "National Vulnerability Database".
The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29859 ‼
📖 Read
via "National Vulnerability Database".
IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could allow a user with physical access to the system to perform unauthorized actions or obtain sensitive information due to insufficient validation and recvocation another user logouting out. IBM X-Force ID: 206081.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25002 ‼
📖 Read
via "National Vulnerability Database".
The Tipsacarrier WordPress plugin through 1.4.4.2 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0649 ‼
📖 Read
via "National Vulnerability Database".
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0418 ‼
📖 Read
via "National Vulnerability Database".
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1239 ‼
📖 Read
via "National Vulnerability Database".
The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1282 ‼
📖 Read
via "National Vulnerability Database".
The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0771 ‼
📖 Read
via "National Vulnerability Database".
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0662 ‼
📖 Read
via "National Vulnerability Database".
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0952 ‼
📖 Read
via "National Vulnerability Database".
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0428 ‼
📖 Read
via "National Vulnerability Database".
The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1269 ‼
📖 Read
via "National Vulnerability Database".
The Fast Flow WordPress plugin before 1.2.11 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1255 ‼
📖 Read
via "National Vulnerability Database".
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1046 ‼
📖 Read
via "National Vulnerability Database".
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25086 ‼
📖 Read
via "National Vulnerability Database".
The Advanced Page Visit Counter WordPress plugin through 5.0.8 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0191 ‼
📖 Read
via "National Vulnerability Database".
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0773 ‼
📖 Read
via "National Vulnerability Database".
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1281 ‼
📖 Read
via "National Vulnerability Database".
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.📖 Read
via "National Vulnerability Database".
🕴 New Regulations in India Require Orgs to Report Cyber Incidents Within 6 Hours 🕴
📖 Read
via "Dark Reading".
CERT-In updates cybersecurity rules to include mandatory reporting, record-keeping, and more.📖 Read
via "Dark Reading".
Darkreading
New Regulations in India Require Orgs to Report Cyber Incidents Within 6 Hours
CERT-In updates cybersecurity rules to include mandatory reporting, record-keeping, and more.
‼ CVE-2021-3750 ‼
📖 Read
via "National Vulnerability Database".
A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-1375 ‼
📖 Read
via "National Vulnerability Database".
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.📖 Read
via "National Vulnerability Database".