Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-1763 | 1 Static Page Extended Project | 1 Static Page Extended | 2022-06-21 | 3.5 LOW | 5.4 MEDIUM |
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings | |||||
CVE-2022-1762 | 1 Webence | 1 Iq Block Country | 2022-06-21 | 5.0 MEDIUM | 7.5 HIGH |
The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers. | |||||
CVE-2022-1761 | 1 Peter\'s Collaboration E-mails Project | 1 Peter\'s Collaboration E-mails | 2022-06-21 | 4.3 MEDIUM | 6.5 MEDIUM |
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more. | |||||
CVE-2022-29524 | 1 Fujielectric | 1 V-server | 2022-06-21 | 6.8 MEDIUM | 7.8 HIGH |
Out-of-bounds write vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |||||
CVE-2022-1900 | 1 Copify | 1 Copify | 2022-06-21 | 6.8 MEDIUM | 8.8 HIGH |
The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2022-31758 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2022-06-21 | 1.9 LOW | 4.7 MEDIUM |
The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||||
CVE-2022-24077 | 1 Naver | 1 Cloud Explorer | 2022-06-21 | 6.9 MEDIUM | 7.8 HIGH |
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection. | |||||
CVE-2022-1777 | 1 Filr Project | 1 Filr | 2022-06-21 | 6.5 MEDIUM | 8.8 HIGH |
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow them to upload arbitrary HTML files as well as delete all files or arbitrary ones. | |||||
CVE-2022-26834 | 1 Rakuten | 1 Casa | 2022-06-21 | 5.0 MEDIUM | 7.5 HIGH |
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default. | |||||
CVE-2022-1773 | 1 Wp Athletics Project | 1 Wp Athletics | 2022-06-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-1594 | 1 Hc Custom Wp-admin Url Project | 1 Hc Custom Wp-admin Url | 2022-06-21 | 4.3 MEDIUM | 4.3 MEDIUM |
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL | |||||
CVE-2022-28387 | 1 Verbatim | 4 Executive Fingerprint Secure Ssd, Executive Fingerprint Secure Ssd Firmware, Fingerprint Secure Portable Hard Drive and 1 more | 2022-06-21 | 2.1 LOW | 4.6 MEDIUM |
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1 and Fingerprint Secure Portable Hard Drive Part Number #53650. | |||||
CVE-2022-1772 | 1 Google Places Reviews Project | 1 Google Places Reviews | 2022-06-21 | 2.1 LOW | 4.8 MEDIUM |
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account. | |||||
CVE-2022-1765 | 1 Hot Linked Image Cacher Project | 1 Hot Linked Image Cacher | 2022-06-21 | 6.8 MEDIUM | 8.8 HIGH |
The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules). | |||||
CVE-2022-1787 | 1 Sideblog Project | 1 Sideblog | 2022-06-21 | 3.5 LOW | 5.4 MEDIUM |
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |||||
CVE-2022-1781 | 1 Posttabs Project | 1 Posttabs | 2022-06-21 | 3.5 LOW | 5.4 MEDIUM |
The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |||||
CVE-2022-1780 | 1 Latex Project | 1 Latex | 2022-06-21 | 3.5 LOW | 5.4 MEDIUM |
The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |||||
CVE-2022-1779 | 1 Auto Delete Posts Project | 1 Auto Delete Posts | 2022-06-21 | 5.8 MEDIUM | 8.1 HIGH |
The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once. | |||||
CVE-2022-28452 | 1 Redplanetcomputers | 1 Laundry Management System | 2022-06-21 | 7.5 HIGH | 9.8 CRITICAL |
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | |||||
CVE-2022-1791 | 1 One Click Plugin Updater Project | 1 One Click Plugin Updater | 2022-06-21 | 5.8 MEDIUM | 8.1 HIGH |
The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check. |