Show filters
275 Total Results
Displaying 61-70 of 275
Sort by:
Attacker Value
Unknown

CVE-2023-2558

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-2557

Disclosure Date: June 09, 2023 (last updated February 25, 2025)
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit an arbitrary custom drop-down currency switcher.
Attacker Value
Unknown

CVE-2023-2555

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create a custom drop-down currency switcher.
Attacker Value
Unknown

CVE-2023-33314

Disclosure Date: May 28, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
Attacker Value
Unknown

CVE-2022-4489

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Attacker Value
Unknown

CVE-2022-4431

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-45434

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.
Attacker Value
Unknown

CVE-2022-45433

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results.
Attacker Value
Unknown

CVE-2022-45432

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.
Attacker Value
Unknown

CVE-2022-45431

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart of remote DSS Server.