| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40347 | Cri | 0.67 | 9.8 | 0.05 | Feb 17, 2023 | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information. | ||
| CVE-2023-24221 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml. | ||
| CVE-2023-24220 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml. | ||
| CVE-2023-24219 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml. | ||
| CVE-2021-43529 | Cri | 0.64 | 9.8 | 0.00 | Feb 16, 2023 | Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with… | ||
| CVE-2022-39952 | Cri | 0.75 | 9.8 | 1.00 | Feb 16, 2023 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or… | ||
| CVE-2022-38375 | Cri | 0.59 | 9.1 | 0.01 | Feb 16, 2023 | An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. | ||
| CVE-2021-42761 | Cri | 0.59 | 9.0 | 0.01 | Feb 16, 2023 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to… | ||
| CVE-2021-42756 | Cri | 0.66 | 9.8 | 0.35 | Feb 16, 2023 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code… | ||
| CVE-2023-23947 | Cri | 0.52 | 9.1 | 0.01 | Feb 16, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one… | ||
| CVE-2023-24238 | Cri | 0.64 | 9.8 | 0.02 | Feb 16, 2023 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules. | ||
| CVE-2023-24236 | Cri | 0.64 | 9.8 | 0.02 | Feb 16, 2023 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules. | ||
| CVE-2023-22579 | Cri | 0.57 | 9.9 | 0.01 | Feb 16, 2023 | Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. | ||
| CVE-2023-22578 | Cri | 0.58 | 10.0 | 0.01 | Feb 16, 2023 | Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | ||
| CVE-2022-3843 | Cri | 0.59 | 9.1 | 0.01 | Feb 16, 2023 | In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters. | ||
| CVE-2022-43969 | Cri | 0.59 | 9.1 | 0.01 | Feb 16, 2023 | Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials. | ||
| CVE-2021-33925 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login. | ||
| CVE-2021-33304 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code. | ||
| CVE-2020-21120 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num. | ||
| CVE-2020-21119 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code. | ||
| CVE-2020-19825 | Cri | 0.62 | 9.6 | 0.01 | Feb 15, 2023 | Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges. | ||
| CVE-2023-22855 | Cri | 0.68 | 9.8 | 0.15 | Feb 15, 2023 | Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of… | ||
| CVE-2023-23465 | Cri | 0.59 | 9.1 | 0.00 | Feb 15, 2023 | Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint. | ||
| CVE-2023-23462 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | Libpeconv – integer overflow, before commit 75b1565 (30/11/2022). | ||
| CVE-2023-23461 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | Libpeconv – access violation, before commit b076013 (30/11/2022). | ||
| CVE-2023-23460 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. | ||
| CVE-2023-23459 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | ||
| CVE-2023-22807 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol. | ||
| CVE-2023-22804 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device. | ||
| CVE-2023-0102 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files. | ||
| CVE-2022-46892 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex. | ||
| CVE-2023-25765 | Cri | 0.57 | 9.9 | 0.01 | Feb 15, 2023 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the… | ||
| CVE-2023-21803 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2023 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability | ||
| CVE-2023-21716 | Cri | 0.70 | 9.8 | 0.85 | Feb 14, 2023 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2023-21692 | Cri | 0.65 | 9.8 | 0.21 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2023-21690 | Cri | 0.66 | 9.8 | 0.28 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2023-21689 | Cri | 0.66 | 9.8 | 0.27 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2023-25725 | Cri | 0.60 | 9.1 | 0.05 | Feb 14, 2023 | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers… | ||
| CVE-2023-24161 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. | ||
| CVE-2023-24160 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function. | ||
| CVE-2023-24159 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function. | ||
| CVE-2023-24482 | Cri | 0.65 | 10.0 | 0.01 | Feb 14, 2023 | A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All… | ||
| CVE-2022-47034 | Cri | 0.00 | 9.8 | 0.01 | Feb 13, 2023 | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication. | ||
| CVE-2023-24646 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2023-24084 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. | ||
| CVE-2023-25718 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled… | ||
| CVE-2023-25717 | Cri | 0.83 | 9.8 | 0.98 | KEV | Feb 13, 2023 | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. | |
| CVE-2023-24188 | Cri | 0.59 | 9.1 | 0.01 | Feb 13, 2023 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. | ||
| CVE-2023-23551 | Cri | 0.59 | 9.1 | 0.01 | Feb 13, 2023 | Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code. | ||
| CVE-2022-4445 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. |
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.
- risk 0.64cvss 9.8epss 0.00
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with…
- risk 0.75cvss 9.8epss 1.00
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or…
- risk 0.59cvss 9.1epss 0.01
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
- risk 0.59cvss 9.0epss 0.01
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to…
- risk 0.66cvss 9.8epss 0.35
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code…
- risk 0.52cvss 9.1epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one…
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
- risk 0.57cvss 9.9epss 0.01
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
- risk 0.58cvss 10.0epss 0.01
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
- risk 0.59cvss 9.1epss 0.01
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
- risk 0.59cvss 9.1epss 0.01
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.
- risk 0.64cvss 9.8epss 0.01
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.
- risk 0.62cvss 9.6epss 0.01
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
- risk 0.68cvss 9.8epss 0.15
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of…
- risk 0.59cvss 9.1epss 0.00
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
- risk 0.64cvss 9.8epss 0.01
Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).
- risk 0.64cvss 9.8epss 0.01
Libpeconv – access violation, before commit b076013 (30/11/2022).
- risk 0.59cvss 9.1epss 0.01
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
- risk 0.59cvss 9.1epss 0.01
Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
- risk 0.64cvss 9.8epss 0.01
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.
- risk 0.59cvss 9.1epss 0.01
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device.
- risk 0.59cvss 9.1epss 0.01
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.
- risk 0.64cvss 9.8epss 0.01
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
- risk 0.57cvss 9.9epss 0.01
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the…
- risk 0.64cvss 9.8epss 0.02
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.85
Microsoft Word Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.21
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.28
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.27
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.60cvss 9.1epss 0.05
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers…
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.
- risk 0.65cvss 10.0epss 0.01
A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All…
- risk 0.00cvss 9.8epss 0.01
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
- risk 0.64cvss 9.8epss 0.01
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled…
- risk 0.83cvss 9.8epss 0.98
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
- risk 0.59cvss 9.1epss 0.01
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
- risk 0.59cvss 9.1epss 0.01
Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.