βΌ CVE-2023-0253 βΌ
π Read
via "National Vulnerability Database".
The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via folder names in versions up to, and including, 4.18.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48113 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3560 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48082 βΌ
π Read
via "National Vulnerability Database".
Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45067 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0576 βΌ
π Read
via "National Vulnerability Database".
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in Yugabyte DB allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel Manipulation, Authentication Abuse.This issue affects Yugabyte DB: v2.17.0.0.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24574 βΌ
π Read
via "National Vulnerability Database".
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to uncontrolled resource consumption by creating permanent home directories for unauthenticated users.π Read
via "National Vulnerability Database".
βΌ CVE-2022-46842 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48140 βΌ
π Read
via "National Vulnerability Database".
DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.php?fmdo=edit&filename.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48130 βΌ
π Read
via "National Vulnerability Database".
Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.π Read
via "National Vulnerability Database".
βΌ CVE-2022-46815 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40692 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48114 βΌ
π Read
via "National Vulnerability Database".
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48079 βΌ
π Read
via "National Vulnerability Database".
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45807 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44585 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab SΓ rl Homepage Pop-up plugin <= 1.2.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48021 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0123 βΌ
π Read
via "National Vulnerability Database".
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.π Read
via "National Vulnerability Database".
βΌ CVE-2022-4634 βΌ
π Read
via "National Vulnerability Database".
All versions prior to Delta ElectronicΓ’β¬β’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23635 βΌ
π Read
via "National Vulnerability Database".
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47132 βΌ
π Read
via "National Vulnerability Database".
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.π Read
via "National Vulnerability Database".