Lucene search

K

Simple Security Vulnerabilities

cve
cve

CVE-2021-42169

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and...

9.8CVSS

9.6AI Score

0.009EPSS

2021-10-22 02:15 PM
40
cve
cve

CVE-2023-28790

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.3...

5.9CVSS

4.8AI Score

0.0004EPSS

2023-09-27 03:18 PM
8
cve
cve

CVE-2023-31076

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6...

7.1CVSS

6AI Score

0.0005EPSS

2023-08-17 09:15 AM
17
cve
cve

CVE-2022-25912

The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of...

9.8CVSS

9.5AI Score

0.012EPSS

2022-12-06 05:15 AM
67
cve
cve

CVE-2022-24433

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary.....

9.8CVSS

9.9AI Score

0.006EPSS

2022-03-11 05:16 PM
69
cve
cve

CVE-2022-24066

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of CVE-2022-24433 which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't...

9.8CVSS

9.6AI Score

0.006EPSS

2022-04-01 08:15 PM
83
cve
cve

CVE-2022-42197

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher...

6.5CVSS

6.3AI Score

0.001EPSS

2022-10-20 01:15 PM
19
10
cve
cve

CVE-2022-0355

Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to...

8.8CVSS

7.3AI Score

0.002EPSS

2022-01-26 04:15 AM
71
cve
cve

CVE-2023-37629

Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to...

9.8CVSS

9.4AI Score

0.104EPSS

2023-07-12 05:15 PM
27
cve
cve

CVE-2023-35089

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-17 02:15 PM
10
cve
cve

CVE-2022-1801

The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam...

7.5CVSS

7.5AI Score

0.001EPSS

2022-06-20 11:15 AM
44
6
cve
cve

CVE-2023-37628

Online Piggery Management System 1.0 is vulnerable to SQL...

9.8CVSS

9.5AI Score

0.001EPSS

2023-07-12 05:15 PM
103
cve
cve

CVE-2023-37630

Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent...

6.1CVSS

6.2AI Score

0.001EPSS

2023-07-12 05:15 PM
19
cve
cve

CVE-2023-27443

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2.9.1...

6.5CVSS

5.2AI Score

0.0005EPSS

2023-06-21 01:15 PM
19
cve
cve

CVE-2023-26515

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-06-16 11:15 AM
15
cve
cve

CVE-2023-34548

Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email...

9.8CVSS

9.8AI Score

0.001EPSS

2023-06-16 03:15 PM
17
cve
cve

CVE-2023-32691

gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this comparison is not...

5.9CVSS

5.6AI Score

0.001EPSS

2023-05-30 04:15 AM
30
cve
cve

CVE-2022-47178

Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7...

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-25 12:15 PM
33
cve
cve

CVE-2022-41544

GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in...

9.8CVSS

9.8AI Score

0.022EPSS

2022-10-18 03:15 PM
42
2
cve
cve

CVE-2023-22709

Cross-Site Request Forgery (CSRF) vulnerability in Atif N SRS Simple Hits Counter plugin <= 1.1.0...

8.8CVSS

8.7AI Score

0.001EPSS

2023-05-22 09:15 AM
20
cve
cve

CVE-2023-25958

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Justin Saad Simple Tooltips plugin <= 2.1.4...

5.9CVSS

4.9AI Score

0.0005EPSS

2023-05-12 04:15 PM
17
cve
cve

CVE-2023-24406

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb ur Rehman Simple PopUp plugin <= 1.8.6...

5.9CVSS

4.9AI Score

0.0005EPSS

2023-05-10 09:15 AM
13
cve
cve

CVE-2023-24376

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-05-08 10:15 PM
14
cve
cve

CVE-2023-26016

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-05-04 01:15 PM
10
cve
cve

CVE-2023-25982

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5...

6.5CVSS

5.2AI Score

0.0005EPSS

2023-05-04 08:15 PM
13
cve
cve

CVE-2023-25484

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-04-25 05:15 PM
11
cve
cve

CVE-2023-23817

Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9...

6.5CVSS

5.2AI Score

0.0005EPSS

2023-04-23 11:15 AM
21
cve
cve

CVE-2022-40032

SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive...

9.8CVSS

10AI Score

0.004EPSS

2023-02-17 02:15 PM
43
cve
cve

CVE-2023-24655

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update...

9.8CVSS

9.7AI Score

0.001EPSS

2023-03-23 01:15 AM
17
cve
cve

CVE-2023-26905

An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via...

9.8CVSS

9.6AI Score

0.001EPSS

2023-03-19 01:15 AM
26
cve
cve

CVE-2023-27040

Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username...

9.8CVSS

9.8AI Score

0.027EPSS

2023-03-16 04:15 PM
22
cve
cve

CVE-2023-24732

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update...

8.8CVSS

8.9AI Score

0.001EPSS

2023-03-15 02:15 PM
22
cve
cve

CVE-2023-24728

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update...

8.8CVSS

8.9AI Score

0.001EPSS

2023-03-15 02:15 PM
16
cve
cve

CVE-2023-24731

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update...

8.8CVSS

8.9AI Score

0.001EPSS

2023-03-15 02:15 PM
17
cve
cve

CVE-2023-24730

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update...

8.8CVSS

8.9AI Score

0.001EPSS

2023-03-15 02:15 PM
18
cve
cve

CVE-2023-24729

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update...

8.8CVSS

8.9AI Score

0.001EPSS

2023-03-15 02:15 PM
16
cve
cve

CVE-2015-9302

The simple-fields plugin before 1.4.11 for WordPress has...

6.1CVSS

6.4AI Score

0.001EPSS

2019-08-13 05:15 PM
28
cve
cve

CVE-2016-10884

The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF...

8.8CVSS

8.8AI Score

0.001EPSS

2019-08-14 04:15 PM
28
cve
cve

CVE-2023-24364

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-27 04:15 PM
32
cve
cve

CVE-2023-24652

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-27 04:15 PM
19
cve
cve

CVE-2023-24651

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration...

5.4CVSS

5.9AI Score

0.001EPSS

2023-02-27 04:15 PM
19
cve
cve

CVE-2023-24653

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-27 04:15 PM
14
cve
cve

CVE-2023-24654

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-27 04:15 PM
17
cve
cve

CVE-2023-24656

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-27 04:15 PM
19
cve
cve

CVE-2017-18499

The simple-membership plugin before 3.5.7 for WordPress has...

6.1CVSS

6.4AI Score

0.001EPSS

2019-08-12 04:15 PM
35
cve
cve

CVE-2023-23026

Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 sales management system 1.0, allows attackers to execute arbitrary code via the product_name and product_price inputs in file...

6.1CVSS

6.2AI Score

0.001EPSS

2023-02-07 11:15 PM
19
cve
cve

CVE-2019-15833

The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected...

6.1CVSS

6.4AI Score

0.001EPSS

2019-08-30 02:15 PM
35
cve
cve

CVE-2021-43657

A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input...

5.4CVSS

5.3AI Score

0.001EPSS

2022-12-22 02:15 AM
35
cve
cve

CVE-2022-3024

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored.....

5.4CVSS

5.2AI Score

0.001EPSS

2022-09-26 01:15 PM
32
2
cve
cve

CVE-2022-45010

Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at...

9.8CVSS

9.7AI Score

0.002EPSS

2022-12-07 02:15 AM
24
Total number of security vulnerabilities432