Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0279 1 Bologer 1 Anycomment 2022-02-28 3.5 LOW 3.1 LOW
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users
CVE-2022-0255 1 Deliciousbrains 1 Database Backup 2022-02-28 6.5 MEDIUM 7.2 HIGH
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue
CVE-2022-0252 1 Givewp 1 Givewp 2022-02-28 4.3 MEDIUM 6.1 MEDIUM
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting
CVE-2022-0234 1 Pluginus 1 Woocs 2022-02-28 4.3 MEDIUM 6.1 MEDIUM
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting
CVE-2022-0313 1 Wow-estore 1 Float Menu 2022-02-28 4.3 MEDIUM 4.3 MEDIUM
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack
CVE-2021-26619 2 Bigfile, Microsoft 2 Bigfileagent, Windows 2022-02-28 6.4 MEDIUM 9.1 CRITICAL
An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users.
CVE-2022-0228 1 Sygnoos 1 Popup Builder 2022-02-28 6.5 MEDIUM 7.2 HIGH
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
CVE-2022-0211 1 Getshieldsecurity 1 Shield Security 2022-02-28 3.5 LOW 4.8 MEDIUM
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
CVE-2022-0199 1 Wpdevart 1 Coming Soon And Maintenance Mode 2022-02-28 4.3 MEDIUM 4.3 MEDIUM
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
CVE-2022-0186 1 Machothemes 1 Image Photo Gallery Final Tiles Grid 2022-02-28 3.5 LOW 5.4 MEDIUM
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard
CVE-2021-3197 3 Debian, Fedoraproject, Saltstack 3 Debian Linux, Fedora, Salt 2022-02-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
CVE-2011-2000 1 Microsoft 6 Internet Explorer, Windows 7, Windows Server 2003 and 3 more 2022-02-28 9.3 HIGH N/A
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Body Element Remote Code Execution Vulnerability."
CVE-2011-1999 1 Microsoft 6 Internet Explorer, Windows 7, Windows Server 2003 and 3 more 2022-02-28 9.3 HIGH N/A
Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."
CVE-2022-0164 1 Wpdevart 1 Coming Soon And Maintenance Mode 2022-02-28 4.0 MEDIUM 4.3 MEDIUM
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users
CVE-2021-39312 1 Trueranker 1 True Ranker 2022-02-28 5.0 MEDIUM 7.5 HIGH
The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.
CVE-2022-0134 1 Bologer 1 Anycomment 2022-02-28 6.8 MEDIUM 8.8 HIGH
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack
CVE-2021-32012 2 Oracle, Sheetjs Project 3 Rest Data Services, Sheetjs, Sheetjs Pro 2022-02-28 4.3 MEDIUM 5.5 MEDIUM
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
CVE-2021-4208 1 Exportfeed 1 Exportfeed 2022-02-28 6.5 MEDIUM 7.2 HIGH
The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using it in a SQL statement, leading to a SQL injection vulnerability exploitable by high privilege users
CVE-2021-25101 1 Anti-malware Security And Brute-force Firewall Project 1 Anti-malware Security And Brute-force Firewall 2022-02-28 3.5 LOW 4.8 MEDIUM
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.
CVE-2021-25100 1 Givewp 1 Givewp 2022-02-28 4.3 MEDIUM 6.1 MEDIUM
The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting