| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33480 | Hig | 0.57 | 8.8 | 0.02 | Nov 7, 2023 | RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by… | ||
| CVE-2023-5709 | Hig | 0.57 | 8.8 | 0.01 | Nov 7, 2023 | The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | ||
| CVE-2023-47510 | Hig | 0.46 | 7.1 | 0.00 | Nov 7, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPSolutions-HQ WPDBSpringClean plugin <= 1.6 versions. | ||
| CVE-2023-46845 | Hig | 0.47 | 7.2 | 0.02 | Nov 7, 2023 | EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be… | ||
| CVE-2023-43886 | Hig | 0.46 | 7.1 | 0.01 | Nov 7, 2023 | A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory. | ||
| CVE-2023-43885 | Hig | 0.53 | 8.1 | 0.01 | Nov 7, 2023 | Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device. | ||
| CVE-2023-42537 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. | ||
| CVE-2023-42536 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. | ||
| CVE-2023-42535 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2023-33074 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory corruption in Audio when SSR event is triggered after music playback is stopped. | ||
| CVE-2023-33061 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame. | ||
| CVE-2023-33059 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. | ||
| CVE-2023-33056 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE. | ||
| CVE-2023-33055 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory Corruption in Audio while invoking callback function in driver from ADSP. | ||
| CVE-2023-33048 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing t2lm buffers. | ||
| CVE-2023-33047 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing no-inherit IES. | ||
| CVE-2023-33031 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | ||
| CVE-2023-28556 | Hig | 0.46 | 7.1 | 0.00 | Nov 7, 2023 | Cryptographic issue in HLOS during key management. | ||
| CVE-2023-28545 | Hig | 0.53 | 8.2 | 0.00 | Nov 7, 2023 | Memory corruption in TZ Secure OS while loading an app ELF. | ||
| CVE-2023-24852 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. | ||
| CVE-2023-41036 | Hig | 0.00 | 7.8 | 0.00 | Nov 7, 2023 | Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead to a privilege escalation. Distributed objects are a concept introduced by Apple which allow one program to vend an interface to… | ||
| CVE-2023-47004 | Hig | 0.57 | 8.8 | 0.01 | Nov 6, 2023 | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication. | ||
| CVE-2023-5454 | Hig | 0.49 | 7.5 | 0.01 | Nov 6, 2023 | The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts. | ||
| CVE-2023-5355 | Hig | 0.53 | 8.1 | 0.01 | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server. | ||
| CVE-2023-5082 | Hig | 0.47 | 7.2 | 0.01 | Nov 6, 2023 | The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it. | ||
| CVE-2023-5719 | Hig | 0.57 | 8.8 | 0.01 | Nov 6, 2023 | The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device. If such a password contains the percent (%) character, invalid values will be included,… | ||
| CVE-2022-48192 | Hig | 0.47 | 7.2 | 0.00 | Nov 6, 2023 | Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application. | ||
| CVE-2023-39345 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in… | ||
| CVE-2023-46728 | Hig | 0.00 | 7.5 | 0.06 | Nov 6, 2023 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.… | ||
| CVE-2023-46251 | Hig | 0.00 | 7.5 | 0.00 | Nov 6, 2023 | MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual… | ||
| CVE-2023-45827 | Hig | 0.41 | 7.3 | 0.01 | Nov 6, 2023 | Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads… | ||
| CVE-2023-44398 | Hig | 0.00 | 8.8 | 0.01 | Nov 6, 2023 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions… | ||
| CVE-2023-41378 | Hig | 0.42 | 7.5 | 0.01 | Nov 6, 2023 | In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed… | ||
| CVE-2023-5950 | Hig | 0.56 | 8.6 | 0.00 | Nov 6, 2023 | Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This… | ||
| CVE-2023-3399 | Hig | 0.55 | 8.5 | 0.00 | Nov 6, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD… | ||
| CVE-2023-47185 | Hig | 0.46 | 7.1 | 0.00 | Nov 6, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. | ||
| CVE-2023-47182 | Hig | 0.46 | 7.1 | 0.00 | Nov 6, 2023 | Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions. | ||
| CVE-2023-46823 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4. | ||
| CVE-2023-46822 | Hig | 0.46 | 7.1 | 0.00 | Nov 6, 2023 | Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions. | ||
| CVE-2023-46821 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This issue affects GD Security Headers: from n/a through 1.7. | ||
| CVE-2023-46084 | Hig | 0.55 | 8.5 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2. | ||
| CVE-2023-45830 | Hig | 0.55 | 8.5 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12. | ||
| CVE-2023-45657 | Hig | 0.55 | 8.5 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3. | ||
| CVE-2023-45074 | Hig | 0.55 | 8.5 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted… | ||
| CVE-2023-45069 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery… | ||
| CVE-2023-45055 | Hig | 0.55 | 8.5 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6. | ||
| CVE-2023-45001 | Hig | 0.55 | 8.5 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriously Simple Stats: from n/a through 1.5.0. | ||
| CVE-2023-41685 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woocommerce Support System: from n/a through 1.2.1. | ||
| CVE-2023-40609 | Hig | 0.53 | 8.2 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3. | ||
| CVE-2023-40207 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. |
- risk 0.57cvss 8.8epss 0.02
RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by…
- risk 0.57cvss 8.8epss 0.01
The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPSolutions-HQ WPDBSpringClean plugin <= 1.6 versions.
- risk 0.47cvss 7.2epss 0.02
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be…
- risk 0.46cvss 7.1epss 0.01
A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.
- risk 0.53cvss 8.1epss 0.01
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
- risk 0.55cvss 8.4epss 0.00
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- risk 0.55cvss 8.4epss 0.00
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio while processing the VOC packet data from ADSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Audio while invoking callback function in driver from ADSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing t2lm buffers.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing no-inherit IES.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS during key management.
- risk 0.53cvss 8.2epss 0.00
Memory corruption in TZ Secure OS while loading an app ELF.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core due to secure memory access by user while loading modem image.
- risk 0.00cvss 7.8epss 0.00
Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead to a privilege escalation. Distributed objects are a concept introduced by Apple which allow one program to vend an interface to…
- risk 0.57cvss 8.8epss 0.01
Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.
- risk 0.49cvss 7.5epss 0.01
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
- risk 0.53cvss 8.1epss 0.01
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
- risk 0.47cvss 7.2epss 0.01
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
- risk 0.57cvss 8.8epss 0.01
The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device. If such a password contains the percent (%) character, invalid values will be included,…
- risk 0.47cvss 7.2epss 0.00
Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.
- risk 0.49cvss 7.6epss 0.01
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…
- risk 0.00cvss 7.5epss 0.06
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.…
- risk 0.00cvss 7.5epss 0.00
MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual…
- risk 0.41cvss 7.3epss 0.01
Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads…
- risk 0.00cvss 8.8epss 0.01
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions…
- risk 0.42cvss 7.5epss 0.01
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed…
- risk 0.56cvss 8.6epss 0.00
Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This…
- risk 0.55cvss 8.5epss 0.00
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD…
- risk 0.46cvss 7.1epss 0.00
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
- risk 0.46cvss 7.1epss 0.00
Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.
- risk 0.49cvss 7.6epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.
- risk 0.49cvss 7.6epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This issue affects GD Security Headers: from n/a through 1.7.
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted…
- risk 0.49cvss 7.6epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery…
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6.
- risk 0.55cvss 8.5epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriously Simple Stats: from n/a through 1.5.0.
- risk 0.49cvss 7.6epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woocommerce Support System: from n/a through 1.2.1.
- risk 0.53cvss 8.2epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3.
- risk 0.49cvss 7.6epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.