Export limit exceeded: 368696 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368696 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-27292 | 1 Opencats | 1 Opencats | 2025-03-21 | 5.4 Medium |
| An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters. | ||||
| CVE-2023-26256 | 1 Stagil | 1 Stagil Navigation | 2025-03-21 | 7.5 High |
| An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system. | ||||
| CVE-2023-0518 | 1 Gitlab | 1 Gitlab | 2025-03-21 | 4.3 Medium |
| An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart. | ||||
| CVE-2023-0405 | 1 Gptaipower | 1 Gpt Ai Power | 2025-03-21 | 5.4 Medium |
| The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts. | ||||
| CVE-2023-0262 | 1 Ljapps | 1 Wp Airbnb Review Slider | 2025-03-21 | 7.7 High |
| The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber. | ||||
| CVE-2023-0098 | 1 Getlasso | 1 Simple Urls | 2025-03-21 | 7.7 High |
| The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber. | ||||
| CVE-2023-0075 | 1 Amazonjs Project | 1 Amazonjs | 2025-03-21 | 6.8 Medium |
| The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2023-0061 | 1 Judge | 1 Product Reviews For Woocommerce | 2025-03-21 | 6.8 Medium |
| The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2022-4512 | 1 Better Font Awesome Project | 1 Better Font Awesome | 2025-03-21 | 6.8 Medium |
| The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2022-4488 | 1 Widgets On Pages Project | 1 Widgets On Pages | 2025-03-21 | 6.8 Medium |
| The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | ||||
| CVE-2022-4471 | 1 Yarpp | 1 Yet Another Related Posts Plugin | 2025-03-21 | 6.8 Medium |
| The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2022-4138 | 1 Gitlab | 1 Gitlab | 2025-03-21 | 6.4 Medium |
| A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project. | ||||
| CVE-2022-46754 | 1 Dell | 1 Wyse Management Suite | 2025-03-21 | 8.7 High |
| Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities. | ||||
| CVE-2023-0263 | 1 Ljapps | 1 Wp Yelp Review Slider | 2025-03-21 | 8.8 High |
| The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber. | ||||
| CVE-2024-39662 | 1 Modernaweb | 1 Black Widgets For Elementor | 2025-03-21 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5. | ||||
| CVE-2021-25069 | 1 W3eden | 1 Download Manager | 2025-03-21 | 8.8 High |
| The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue | ||||
| CVE-2022-2168 | 1 W3eden | 1 Download Manager | 2025-03-21 | 6.1 Medium |
| The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting | ||||
| CVE-2023-1524 | 1 W3eden | 1 Download Manager | 2025-03-21 | 6.5 Medium |
| The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password. | ||||
| CVE-2023-24086 | 1 Slims Project | 1 Slims | 2025-03-21 | 6.1 Medium |
| SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView. | ||||
| CVE-2023-24084 | 1 Chikoi Project | 1 Chikoi | 2025-03-21 | 9.8 Critical |
| ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. | ||||