| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1000 | Hig | 0.51 | 7.8 | 0.00 | Mar 30, 2022 | In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-1155 | Hig | 0.41 | 7.4 | 0.01 | Mar 30, 2022 | Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10. | ||
| CVE-2022-1154 | Hig | 0.00 | 7.8 | 0.01 | Mar 30, 2022 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. | ||
| CVE-2022-23868 | Hig | 0.51 | 7.8 | 0.01 | Mar 30, 2022 | RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file. | ||
| CVE-2022-25598 | Hig | 0.49 | 7.5 | 0.02 | Mar 30, 2022 | Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. | ||
| CVE-2022-27816 | — | Hig | 0.39 | 7.1 | 0.00 | Mar 30, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. | |
| CVE-2020-24771 | Hig | 0.49 | 7.5 | 0.02 | Mar 30, 2022 | Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content. | ||
| CVE-2022-27815 | — | Hig | 0.44 | 7.8 | 0.01 | Mar 30, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service. | |
| CVE-2022-27432 | Hig | 0.57 | 8.8 | 0.01 | Mar 30, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover. | ||
| CVE-2015-3298 | Hig | 0.57 | 8.8 | 0.01 | Mar 30, 2022 | Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated. | ||
| CVE-2021-44082 | Hig | 0.54 | 8.3 | 0.03 | Mar 29, 2022 | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file… | ||
| CVE-2022-21821 | Hig | 0.51 | 7.8 | 0.02 | Mar 29, 2022 | NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to… | ||
| CVE-2021-43109 | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2022 | An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php. | ||
| CVE-2022-26839 | Hig | 0.51 | 7.8 | 0.00 | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files. | ||
| CVE-2022-22941 | Hig | 0.57 | 8.8 | 0.01 | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no… | ||
| CVE-2022-22936 | Hig | 0.57 | 8.8 | 0.01 | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be… | ||
| CVE-2022-22934 | Hig | 0.57 | 8.8 | 0.01 | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data. | ||
| CVE-2022-1050 | Hig | 0.57 | 8.8 | 0.00 | Mar 29, 2022 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition. | ||
| CVE-2021-44081 | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2022 | A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service. | ||
| CVE-2022-1055 | Hig | 0.51 | 7.8 | 0.01 | Mar 29, 2022 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 | ||
| CVE-2022-28155 | — | Hig | 0.53 | 8.1 | 0.01 | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| CVE-2022-28154 | Hig | 0.53 | 8.1 | 0.01 | Mar 29, 2022 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-28150 | Hig | 0.57 | 8.8 | 0.01 | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job. | ||
| CVE-2022-28142 | — | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2022 | Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues. | |
| CVE-2022-28140 | Hig | 0.46 | 8.1 | 0.01 | Mar 29, 2022 | Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-28136 | Hig | 0.50 | 8.8 | 0.01 | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | ||
| CVE-2022-1032 | Hig | 0.00 | 7.2 | 0.02 | Mar 29, 2022 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2022-1084 | Hig | 0.48 | 7.3 | 0.01 | Mar 29, 2022 | A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched… | ||
| CVE-2022-1083 | — | Hig | 0.48 | 7.3 | 0.01 | Mar 29, 2022 | A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc… | |
| CVE-2022-1082 | Hig | 0.48 | 7.3 | 0.01 | Mar 29, 2022 | A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads to sql injection. The… | ||
| CVE-2022-1080 | Hig | 0.48 | 7.3 | 0.01 | Mar 29, 2022 | A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely. | ||
| CVE-2022-1078 | Hig | 0.48 | 7.3 | 0.01 | Mar 29, 2022 | A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx)… | ||
| CVE-2022-1073 | Hig | 0.48 | 7.3 | 0.01 | Mar 29, 2022 | A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely. | ||
| CVE-2021-44581 | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2022 | An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. | ||
| CVE-2022-26642 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter. | ||
| CVE-2022-26641 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter. | ||
| CVE-2022-26640 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter. | ||
| CVE-2022-26639 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter. | ||
| CVE-2022-24789 | Hig | 0.49 | 7.6 | 0.01 | Mar 28, 2022 | C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The… | ||
| CVE-2021-43103 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43102 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43101 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43100 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43098 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. | ||
| CVE-2021-43097 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code. | ||
| CVE-2022-27658 | Hig | 0.49 | 7.5 | 0.01 | Mar 28, 2022 | Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks. | ||
| CVE-2022-0427 | Hig | 0.50 | 7.7 | 0.01 | Mar 28, 2022 | Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover | ||
| CVE-2022-0770 | Hig | 0.57 | 8.8 | 0.01 | Mar 28, 2022 | The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker… | ||
| CVE-2022-0499 | Hig | 0.57 | 8.8 | 0.01 | Mar 28, 2022 | The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones. | ||
| CVE-2021-25068 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard |
- risk 0.51cvss 7.8epss 0.00
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.41cvss 7.4epss 0.01
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
- risk 0.00cvss 7.8epss 0.01
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
- risk 0.51cvss 7.8epss 0.01
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
- risk 0.49cvss 7.5epss 0.02
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.
- risk 0.39cvss 7.1epss 0.00
SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.
- risk 0.49cvss 7.5epss 0.02
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
- risk 0.44cvss 7.8epss 0.01
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
- risk 0.57cvss 8.8epss 0.01
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
- risk 0.54cvss 8.3epss 0.03
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file…
- risk 0.51cvss 7.8epss 0.02
NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to…
- risk 0.49cvss 7.5epss 0.01
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
- risk 0.51cvss 7.8epss 0.00
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
- risk 0.57cvss 8.8epss 0.00
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
- risk 0.49cvss 7.5epss 0.01
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.
- risk 0.51cvss 7.8epss 0.01
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
- risk 0.53cvss 8.1epss 0.01
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.53cvss 8.1epss 0.01
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job.
- risk 0.49cvss 7.5epss 0.01
Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues.
- risk 0.46cvss 8.1epss 0.01
Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.50cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
- risk 0.00cvss 7.2epss 0.02
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.48cvss 7.3epss 0.01
A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched…
- risk 0.48cvss 7.3epss 0.01
A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc…
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads to sql injection. The…
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely.
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx)…
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
- risk 0.49cvss 7.5epss 0.01
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
- risk 0.47cvss 7.2epss 0.01
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
- risk 0.47cvss 7.2epss 0.01
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
- risk 0.47cvss 7.2epss 0.01
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
- risk 0.47cvss 7.2epss 0.01
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
- risk 0.49cvss 7.6epss 0.01
C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The…
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.01
A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
- risk 0.47cvss 7.2epss 0.02
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.
- risk 0.49cvss 7.5epss 0.01
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
- risk 0.50cvss 7.7epss 0.01
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover
- risk 0.57cvss 8.8epss 0.01
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker…
- risk 0.57cvss 8.8epss 0.01
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.
- risk 0.47cvss 7.2epss 0.01
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard