Show filters
59 Total Results
Displaying 11-20 of 59
Sort by:
Attacker Value
Unknown
CVE-2023-41663
Disclosure Date: September 29, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Giovambattista Fazioli WP Bannerize Pro plugin <= 1.6.9 versions.
0
Attacker Value
Unknown
CVE-2023-2529
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
0
Attacker Value
Unknown
CVE-2023-23875
Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Himanshu Bing Site Verification plugin using Meta Tag plugin <= 1.0 versions.
0
Attacker Value
Unknown
CVE-2022-46867
Disclosure Date: March 17, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Chasil Universal Star Rating plugin <= 2.1.0 version.
0
Attacker Value
Unknown
CVE-2022-3847
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin or editor add Stored XSS payloads via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-29503
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-36285
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-34648
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-30295
Disclosure Date: May 06, 2022 (last updated February 23, 2025)
uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.
0
Attacker Value
Unknown
CVE-2021-27419
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0