Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-29683 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del. | |||||
CVE-2022-29682 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del. | |||||
CVE-2022-29681 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del. | |||||
CVE-2022-29680 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del. | |||||
CVE-2022-29676 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | |||||
CVE-2022-29670 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del. | |||||
CVE-2022-29669 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 8.8 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan. | |||||
CVE-2022-29667 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 8.8 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos. | |||||
CVE-2022-29666 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | |||||
CVE-2022-29665 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save. | |||||
CVE-2022-29664 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 8.8 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save. | |||||
CVE-2022-29663 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy. | |||||
CVE-2022-29662 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. | |||||
CVE-2022-29661 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. | |||||
CVE-2022-29660 | 1 Chshcms | 1 Cscms Music Portal System | 2022-05-27 | 7.5 HIGH | 9.8 CRITICAL |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | |||||
CVE-2022-1825 | 1 Collectiveaccess | 1 Providence | 2022-05-27 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. | |||||
CVE-2022-1298 | 1 Wpshopmart | 1 Tabs Responsive | 2022-05-27 | 3.5 LOW | 4.8 MEDIUM |
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-1268 | 1 Donate Extra Project | 1 Donate Extra | 2022-05-27 | 4.3 MEDIUM | 6.1 MEDIUM |
The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting | |||||
CVE-2022-1221 | 1 Gwyn\'s Imagemap Selector Project | 1 Gwyn\'s Imagemap Selector | 2022-05-27 | 4.3 MEDIUM | 6.1 MEDIUM |
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting. | |||||
CVE-2022-1218 | 1 Duogeek | 1 Domain Replace | 2022-05-27 | 4.3 MEDIUM | 6.1 MEDIUM |
The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |