Export limit exceeded: 366330 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (366330 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-0518 | 1 Gitlab | 1 Gitlab | 2025-03-21 | 4.3 Medium |
| An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart. | ||||
| CVE-2023-0405 | 1 Gptaipower | 1 Gpt Ai Power | 2025-03-21 | 5.4 Medium |
| The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts. | ||||
| CVE-2023-0262 | 1 Ljapps | 1 Wp Airbnb Review Slider | 2025-03-21 | 7.7 High |
| The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber. | ||||
| CVE-2023-0098 | 1 Getlasso | 1 Simple Urls | 2025-03-21 | 7.7 High |
| The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber. | ||||
| CVE-2023-0075 | 1 Amazonjs Project | 1 Amazonjs | 2025-03-21 | 6.8 Medium |
| The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2023-0061 | 1 Judge | 1 Product Reviews For Woocommerce | 2025-03-21 | 6.8 Medium |
| The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2022-4512 | 1 Better Font Awesome Project | 1 Better Font Awesome | 2025-03-21 | 6.8 Medium |
| The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2022-4488 | 1 Widgets On Pages Project | 1 Widgets On Pages | 2025-03-21 | 6.8 Medium |
| The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | ||||
| CVE-2022-4471 | 1 Yarpp | 1 Yet Another Related Posts Plugin | 2025-03-21 | 6.8 Medium |
| The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2022-4138 | 1 Gitlab | 1 Gitlab | 2025-03-21 | 6.4 Medium |
| A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project. | ||||
| CVE-2022-46754 | 1 Dell | 1 Wyse Management Suite | 2025-03-21 | 8.7 High |
| Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities. | ||||
| CVE-2023-0263 | 1 Ljapps | 1 Wp Yelp Review Slider | 2025-03-21 | 8.8 High |
| The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber. | ||||
| CVE-2024-39662 | 1 Modernaweb | 1 Black Widgets For Elementor | 2025-03-21 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5. | ||||
| CVE-2021-25069 | 1 W3eden | 1 Download Manager | 2025-03-21 | 8.8 High |
| The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue | ||||
| CVE-2022-2168 | 1 W3eden | 1 Download Manager | 2025-03-21 | 6.1 Medium |
| The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting | ||||
| CVE-2023-1524 | 1 W3eden | 1 Download Manager | 2025-03-21 | 6.5 Medium |
| The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password. | ||||
| CVE-2023-24086 | 1 Slims Project | 1 Slims | 2025-03-21 | 6.1 Medium |
| SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView. | ||||
| CVE-2023-24084 | 1 Chikoi Project | 1 Chikoi | 2025-03-21 | 9.8 Critical |
| ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. | ||||
| CVE-2023-22854 | 1 Mitel | 1 Micontact Center Business | 2025-03-21 | 9.1 Critical |
| The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information. | ||||
| CVE-2023-22367 | 1 Ichiranusa | 1 Ichiran | 2025-03-21 | 5.9 Medium |
| Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack. | ||||