Show filters
35 Total Results
Displaying 1-10 of 35
Sort by:
Attacker Value
Unknown
CVE-2023-48332
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Tech Banker Mail Bank - #1 Mail SMTP Plugin for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mail Bank - #1 Mail SMTP Plugin for WordPress: from n/a through 4.0.14.
0
Attacker Value
Unknown
CVE-2023-28165
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Tech Banker Backup Bank: WordPress Backup Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup Bank: WordPress Backup Plugin: from n/a through 4.0.28.
0
Attacker Value
Unknown
CVE-2024-9375
Disclosure Date: October 04, 2024 (last updated October 12, 2024)
The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.36. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-1688
Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.
0
Attacker Value
Unknown
CVE-2022-3350
Disclosure Date: October 25, 2022 (last updated October 08, 2023)
The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-30545
Disclosure Date: October 12, 2022 (last updated December 22, 2024)
Auth. Reflected Cross-Site Scripting (XSS) vulnerability in 5 Anker Connect plugin <= 1.2.6 on WordPress.
0
Attacker Value
Unknown
CVE-2022-29503
Disclosure Date: September 22, 2022 (last updated October 08, 2023)
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-21806
Disclosure Date: June 15, 2022 (last updated October 07, 2023)
A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.
0
Attacker Value
Unknown
CVE-2022-25989
Disclosure Date: May 05, 2022 (last updated November 29, 2024)
An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-26073
Disclosure Date: May 05, 2022 (last updated November 29, 2024)
A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.
0