Lucene search

K

Search Security Vulnerabilities

cve
cve

CVE-2022-4741

A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText. The manipulation leads to uncontrolled memory allocation. The attack may be initiated remotely. Upgrading to version 1.2.1 is...

6.5CVSS

6.4AI Score

0.002EPSS

2022-12-25 08:15 PM
39
cve
cve

CVE-2022-4643

A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. Upgrading to version 1.2.1....

9.8CVSS

9.8AI Score

0.002EPSS

2022-12-21 10:15 PM
39
cve
cve

CVE-2023-3005

A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the...

6.1CVSS

6AI Score

0.002EPSS

2023-05-31 09:15 AM
29
cve
cve

CVE-2024-0251

The Advanced Woo Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search parameter in all versions up to, and including, 2.96 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web.....

6.1CVSS

6.2AI Score

0.004EPSS

2024-01-13 08:15 AM
13
cve
cve

CVE-2023-32592

Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Search plugin <= 1.0.2...

8.8CVSS

8.7AI Score

0.001EPSS

2023-11-09 10:15 PM
7
cve
cve

CVE-2023-1435

The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as...

6.1CVSS

6.1AI Score

0.001EPSS

2023-04-24 07:15 PM
24
cve
cve

CVE-2018-7603

In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). The module doesn't sufficiently filter user-entered....

6.1CVSS

6.1AI Score

0.001EPSS

2019-01-15 10:29 PM
24
cve
cve

CVE-2023-1420

The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such.....

6.1CVSS

6.1AI Score

0.001EPSS

2023-04-24 07:15 PM
36
cve
cve

CVE-2022-38456

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3...

7.5CVSS

7.4AI Score

0.001EPSS

2023-03-15 03:15 PM
33
cve
cve

CVE-2023-2452

The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

4.4CVSS

4.3AI Score

0.001EPSS

2023-06-09 06:16 AM
23
cve
cve

CVE-2022-4649

The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2023-01-30 09:15 PM
18
cve
cve

CVE-2022-29316

Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via...

9.8CVSS

9.7AI Score

0.001EPSS

2022-05-11 01:15 PM
49
4
cve
cve

CVE-2021-27999

A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the...

4.9CVSS

5.6AI Score

0.001EPSS

2021-08-19 02:39 PM
17
8
cve
cve

CVE-2023-35783

The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed...

6.3CVSS

5.9AI Score

0.001EPSS

2023-06-16 03:15 PM
18
cve
cve

CVE-2022-47447

Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8...

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-24 05:15 PM
24
cve
cve

CVE-2022-47587

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.5...

5.9CVSS

4.9AI Score

0.0005EPSS

2023-05-10 11:15 AM
17
cve
cve

CVE-2023-23832

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10...

6.5CVSS

5.2AI Score

0.0005EPSS

2023-04-23 11:15 AM
10
cve
cve

CVE-2019-13418

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly...

7.5CVSS

7.5AI Score

0.002EPSS

2019-08-12 10:15 PM
50
cve
cve

CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is...

5.3CVSS

5.2AI Score

0.001EPSS

2019-08-12 09:15 PM
50
cve
cve

CVE-2015-6752

Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search index is configured to use the HTML filter processor, allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified.....

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
16
cve
cve

CVE-2022-36282

Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at...

5.4CVSS

5.2AI Score

0.001EPSS

2022-08-23 04:15 PM
37
4
cve
cve

CVE-2022-35162

Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the CATEGORY parameter at...

4.8CVSS

5AI Score

0.001EPSS

2022-08-05 09:15 PM
31
3
cve
cve

CVE-2022-35163

Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at...

4.8CVSS

5AI Score

0.001EPSS

2022-08-05 09:15 PM
32
3
cve
cve

CVE-2022-25303

The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the flask.render_template...

6.1CVSS

5.9AI Score

0.001EPSS

2022-07-12 03:15 PM
51
8
cve
cve

CVE-2022-25872

All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated...

5.3CVSS

5.2AI Score

0.001EPSS

2022-06-17 08:15 PM
43
6
cve
cve

CVE-2022-22138

All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the...

7.5CVSS

7.4AI Score

0.001EPSS

2022-06-17 08:15 PM
62
11
cve
cve

CVE-2022-32017

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
45
4
cve
cve

CVE-2022-32018

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.3AI Score

0.011EPSS

2022-06-02 04:15 PM
52
4
cve
cve

CVE-2022-32013

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
38
5
cve
cve

CVE-2022-32015

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.3AI Score

0.011EPSS

2022-06-02 04:15 PM
46
4
cve
cve

CVE-2022-32010

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
54
2
cve
cve

CVE-2022-32012

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
44
3
cve
cve

CVE-2022-32016

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
42
4
cve
cve

CVE-2022-32014

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
45
2
cve
cve

CVE-2022-32008

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
46
4
cve
cve

CVE-2022-32007

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.3AI Score

0.011EPSS

2022-06-02 04:15 PM
49
4
cve
cve

CVE-2022-32011

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via...

7.2CVSS

7.4AI Score

0.001EPSS

2022-06-02 04:15 PM
50
4
cve
cve

CVE-2021-36869

Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter:...

6.1CVSS

6AI Score

0.001EPSS

2021-10-21 09:15 PM
37
cve
cve

CVE-2021-38348

The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arbitrary web scripts, in versions up to and including...

6.1CVSS

6AI Score

0.001EPSS

2021-09-10 02:15 PM
23
cve
cve

CVE-2021-28000

A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address...

4.8CVSS

5.5AI Score

0.001EPSS

2021-08-19 02:39 PM
17
8
cve
cve

CVE-2020-36461

An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for...

8.1CVSS

8AI Score

0.002EPSS

2021-08-08 06:15 AM
84
4
cve
cve

CVE-2021-20689

Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified...

6.1CVSS

6.1AI Score

0.001EPSS

2021-04-07 08:15 AM
17
3
cve
cve

CVE-2021-20690

Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified...

6.1CVSS

6.1AI Score

0.001EPSS

2021-04-07 08:15 AM
18
3
cve
cve

CVE-2021-20691

Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified...

6.1CVSS

6.1AI Score

0.001EPSS

2021-04-07 08:15 AM
20
3
cve
cve

CVE-2021-3278

Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login...

9.8CVSS

10AI Score

0.017EPSS

2021-01-26 06:16 PM
49
2
cve
cve

CVE-2020-15517

The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows...

5.4CVSS

5.5AI Score

0.001EPSS

2020-07-07 02:15 PM
30
cve
cve

CVE-2020-12104

The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any...

8.8CVSS

9AI Score

0.001EPSS

2020-05-05 03:15 PM
65
cve
cve

CVE-2020-12070

The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to...

7.5CVSS

7.1AI Score

0.003EPSS

2020-04-24 11:15 PM
119
cve
cve

CVE-2020-11548

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is...

9.8CVSS

9.8AI Score

0.043EPSS

2020-04-05 12:15 AM
117
cve
cve

CVE-2019-15895

search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options...

7.5CVSS

7.6AI Score

0.001EPSS

2019-09-09 01:15 PM
21
Total number of security vulnerabilities80