Lucene search

K

Digital Security Vulnerabilities

cve
cve

CVE-2024-22168

A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to...

6.2AI Score

0.0004EPSS

2024-06-24 11:15 PM
24
cve
cve

CVE-2022-45832

Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through...

6.5CVSS

6.6AI Score

0.0004EPSS

2024-06-19 03:15 PM
21
cve
cve

CVE-2024-21727

XSS vulnerability in DP Calendar component for...

6AI Score

0.0004EPSS

2024-02-15 07:15 AM
55
cve
cve

CVE-2024-30506

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Stored XSS.This issue affects All In One Redirection: from n/a through...

7.1CVSS

9.1AI Score

0.0004EPSS

2024-03-29 03:15 PM
32
cve
cve

CVE-2023-49852

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through...

6.5CVSS

7.1AI Score

0.0004EPSS

2024-06-04 12:15 PM
2
cve
cve

CVE-2023-51684

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files...

6.5CVSS

5.4AI Score

0.0004EPSS

2024-02-01 11:15 AM
23
cve
cve

CVE-2024-4433

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through...

5.9CVSS

6.6AI Score

0.0004EPSS

2024-05-02 04:15 PM
31
cve
cve

CVE-2024-29791

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through...

7.1CVSS

9.3AI Score

0.0004EPSS

2024-03-27 01:15 PM
27
cve
cve

CVE-2024-5514

MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend system without...

9.8CVSS

7.1AI Score

0.001EPSS

2024-05-30 03:15 AM
28
cve
cve

CVE-2024-31113

Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-05-14 03:24 PM
7
cve
cve

CVE-2024-31293

Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through...

4.3CVSS

9.2AI Score

0.0004EPSS

2024-04-12 01:15 PM
24
cve
cve

CVE-2024-32100

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through...

5.3CVSS

6.7AI Score

0.0004EPSS

2024-05-14 03:34 PM
20
cve
cve

CVE-2024-23911

Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted...

6.7AI Score

0.0004EPSS

2024-04-15 11:15 AM
38
cve
cve

CVE-2006-1098

Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that.....

8.5AI Score

0.006EPSS

2006-03-09 01:06 PM
19
cve
cve

CVE-2006-1096

Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a...

5.7AI Score

0.011EPSS

2006-03-09 01:06 PM
19
cve
cve

CVE-2020-36762

A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection. Upgrading to version...

9.8CVSS

9.9AI Score

0.007EPSS

2023-07-18 03:15 PM
26
cve
cve

CVE-2013-4732

The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676...

6.9AI Score

0.008EPSS

2022-10-03 04:14 PM
24
cve
cve

CVE-2023-22819

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi...

4.9CVSS

5.1AI Score

0.001EPSS

2024-02-05 10:15 PM
9
cve
cve

CVE-2024-28957

Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the...

7AI Score

0.0004EPSS

2024-04-15 11:15 AM
29
cve
cve

CVE-2024-28894

Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted...

6.7AI Score

0.0004EPSS

2024-04-15 11:15 AM
27
cve
cve

CVE-2024-22156

Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through...

6.5CVSS

6.5AI Score

0.0004EPSS

2024-03-26 01:15 PM
34
cve
cve

CVE-2006-2395

PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has...

7.6AI Score

0.042EPSS

2006-05-16 01:02 AM
24
cve
cve

CVE-2023-22817

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing.....

5.5CVSS

6AI Score

0.0005EPSS

2024-02-05 10:15 PM
8
cve
cve

CVE-2024-22154

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through...

7.5CVSS

7.6AI Score

0.001EPSS

2024-01-24 01:15 PM
16
cve
cve

CVE-2022-36418

Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through...

9.8CVSS

9.3AI Score

0.001EPSS

2024-01-17 04:15 PM
16
cve
cve

CVE-2022-22995

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary...

10CVSS

9.5AI Score

0.007EPSS

2022-03-25 11:15 PM
161
cve
cve

CVE-2023-49159

Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: from n/a through...

7.5CVSS

7.7AI Score

0.001EPSS

2023-12-15 04:15 PM
34
cve
cve

CVE-2023-48737

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital Grup TriPay Payment Gateway allows Stored XSS.This issue affects TriPay Payment Gateway: from n/a through...

5.9CVSS

5.4AI Score

0.0004EPSS

2023-11-30 11:15 AM
18
cve
cve

CVE-2023-6248

The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks the location, video and diagnostic data from each...

10CVSS

9.7AI Score

0.002EPSS

2023-11-21 10:15 PM
21
cve
cve

CVE-2023-28167

Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3...

8.8CVSS

8.7AI Score

0.001EPSS

2023-11-12 11:15 PM
8
cve
cve

CVE-2023-47516

Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Widget: from n/a through...

7.1CVSS

6.4AI Score

0.0005EPSS

2023-11-13 04:15 AM
32
cve
cve

CVE-2022-43494

An unauthorized user could be able to read any file on the system, potentially exposing sensitive...

7.5CVSS

6.2AI Score

0.001EPSS

2023-01-18 12:15 AM
34
cve
cve

CVE-2022-38469

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and...

7.5CVSS

7.4AI Score

0.001EPSS

2023-01-18 12:15 AM
29
cve
cve

CVE-2023-0598

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI...

9.8CVSS

9.5AI Score

0.002EPSS

2023-03-16 08:15 PM
27
cve
cve

CVE-2022-47610

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6...

5.9CVSS

4.8AI Score

0.001EPSS

2023-03-29 07:15 PM
22
cve
cve

CVE-2022-46732

Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication...

9.8CVSS

9.5AI Score

0.002EPSS

2023-01-18 12:15 AM
48
cve
cve

CVE-2022-46660

An unauthorized user could alter or write files with full control over the path and content of the...

7.5CVSS

6.5AI Score

0.001EPSS

2023-01-18 12:15 AM
27
cve
cve

CVE-2022-46331

An unauthorized user could possibly delete any file on the...

8.1CVSS

8AI Score

0.001EPSS

2023-01-18 12:15 AM
28
cve
cve

CVE-2023-25794

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0...

5.9CVSS

4.9AI Score

0.001EPSS

2023-03-20 11:15 AM
25
cve
cve

CVE-2022-2460

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated...

9.8CVSS

10AI Score

0.002EPSS

2022-08-08 02:15 PM
35
5
cve
cve

CVE-2023-46204

Cross-Site Request Forgery (CSRF) vulnerability in Muller Digital Inc. Duplicate Theme plugin <= 0.1.6...

8.8CVSS

8.8AI Score

0.001EPSS

2023-10-25 06:17 PM
11
cve
cve

CVE-2023-45065

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <= 1.42...

7.1CVSS

6AI Score

0.0005EPSS

2023-10-18 01:15 PM
26
cve
cve

CVE-2023-34207

Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP...

9.9CVSS

8.3AI Score

0.001EPSS

2023-10-17 04:15 AM
36
cve
cve

CVE-2023-34210

SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL...

8.8CVSS

8.9AI Score

0.001EPSS

2023-10-17 05:15 AM
13
cve
cve

CVE-2023-34209

Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to obtain the absolute path via unencrypted VIEWSTATE...

5CVSS

4.4AI Score

0.001EPSS

2023-10-17 05:15 AM
15
cve
cve

CVE-2023-34208

Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arbitrary directories via a crafted ZIP...

6.5CVSS

6.2AI Score

0.001EPSS

2023-10-17 04:15 AM
37
cve
cve

CVE-2023-44689

e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result,...

4.3CVSS

4.7AI Score

0.0005EPSS

2023-10-11 01:15 AM
19
cve
cve

CVE-2022-22988

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to...

9.1CVSS

9AI Score

0.002EPSS

2022-01-13 09:15 PM
38
cve
cve

CVE-2022-22989

My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow...

9.8CVSS

9.5AI Score

0.003EPSS

2022-01-13 09:15 PM
82
cve
cve

CVE-2023-41692

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3...

7.1CVSS

6AI Score

0.0005EPSS

2023-10-02 08:15 AM
16
Total number of security vulnerabilities173