Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-4162 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4161 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4160 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4159 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4165 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4164 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4163 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4166 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4267 | 1 Speakdigital | 1 Bulk Delete Users By Email | 2023-01-04 | N/A | 6.1 MEDIUM |
The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-4266 | 1 Speakdigital | 1 Bulk Delete Users By Email | 2023-01-04 | N/A | 6.5 MEDIUM |
The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attack | |||||
CVE-2022-4047 | 1 Wpswings | 1 Return Refund And Exchange For Woocommerce | 2023-01-04 | N/A | 9.8 CRITICAL |
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE | |||||
CVE-2022-4120 | 1 Trumani | 1 Stop Spammers | 2023-01-04 | N/A | 9.8 CRITICAL |
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain | |||||
CVE-2022-4117 | 1 Iws-geo-form-fields Project | 1 Iws-geo-form-fields | 2023-01-04 | N/A | 9.8 CRITICAL |
The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. | |||||
CVE-2022-4243 | 1 Wpscoop | 1 Imageinject | 2023-01-04 | N/A | 4.8 MEDIUM |
The ImageInject WordPress plugin through TODO does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2022-4242 | 1 Ljapps | 1 Wp Google Review Slider | 2023-01-04 | N/A | 4.8 MEDIUM |
The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2022-4239 | 1 Amentotech | 1 Workreap | 2023-01-04 | N/A | 6.5 MEDIUM |
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id. | |||||
CVE-2022-4151 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-4150 | 1 Contest-gallery | 1 Contest Gallery | 2023-01-04 | N/A | 6.5 MEDIUM |
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. | |||||
CVE-2022-33324 | 1 Mitsubishi | 38 Melipc Mi5122-vw, Melipc Mi5122-vw Firmware, Melsec Iq-l L04 Hcpu and 35 more | 2023-01-04 | N/A | 7.5 HIGH |
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU all versions, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V all versions, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU all versions and Mitsubishi Electric Corporation MELIPC Series MI5122-VW all versions allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery. | |||||
CVE-2021-4280 | 1 Styler Praat Scripts Project | 1 Styler Praat Scripts | 2023-01-04 | N/A | 6.5 MEDIUM |
A vulnerability was found in styler_praat_scripts. It has been classified as problematic. Affected is an unknown function of the file file_segmenter.praat of the component Slash Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The name of the patch is 0cad44aa4a3eb0ecdba071c10eaff16023d8b35f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216780. |