‼ CVE-2022-33901 ‼
📖 Read
via "National Vulnerability Database".
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27235 ‼
📖 Read
via "National Vulnerability Database".
Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30998 ‼
📖 Read
via "National Vulnerability Database".
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-33960 ‼
📖 Read
via "National Vulnerability Database".
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0979 ‼
📖 Read
via "National Vulnerability Database".
Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.📖 Read
via "National Vulnerability Database".
‼ CVE-2017-20141 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Itech Movie Portal Script 7.36. This affects an unknown part of the file /movie.php. The manipulation of the argument f leads to sql injection (Union). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28879 ‼
📖 Read
via "National Vulnerability Database".
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aepack.dll component can crash the scanning engine.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2511 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2510 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0980 ‼
📖 Read
via "National Vulnerability Database".
Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34839 ‼
📖 Read
via "National Vulnerability Database".
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34650 ‼
📖 Read
via "National Vulnerability Database".
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-33191 ‼
📖 Read
via "National Vulnerability Database".
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34853 ‼
📖 Read
via "National Vulnerability Database".
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25759 ‼
📖 Read
via "National Vulnerability Database".
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.📖 Read
via "National Vulnerability Database".
🕴 Understanding Proposed SEC Rules Through an ESG Lens 🕴
📖 Read
via "Dark Reading".
Cyber threats are putting environmental, social, and governance discussions at the forefront of board meetings and C-suite discussions around the globe.📖 Read
via "Dark Reading".
Dark Reading
Understanding Proposed SEC Rules Through an ESG Lens
Cyber threats are putting environmental, social, and governance discussions at the forefront of board meetings and C-suite discussions around the globe.
‼ CVE-2022-34113 ‼
📖 Read
via "National Vulnerability Database".
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34112 ‼
📖 Read
via "National Vulnerability Database".
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34114 ‼
📖 Read
via "National Vulnerability Database".
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36408 ‼
📖 Read
via "National Vulnerability Database".
PrestaShop 1.6.0.10 through 1.7.x before 1.7.8.2 allows remote attackers to execute arbitrary code, aka a "previously unknown vulnerability chain" related to SQL injection, as exploited in the wild in July 2022.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34115 ‼
📖 Read
via "National Vulnerability Database".
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.📖 Read
via "National Vulnerability Database".