Lucene search

K

Handsome Testimonials & Reviews Project Security Vulnerabilities

osv
osv

CVE-2022-4717

The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high...

5.4CVSS

5.4AI Score

0.001EPSS

2023-02-06 08:15 PM
3
wpvulndb
wpvulndb

Testimonials Widget <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via testimonials Shortcode

Description The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...

6.4CVSS

5.8AI Score

0.0004EPSS

2024-06-05 12:00 AM
nuclei
nuclei

Testimonials by BestWebSoft < 0.1.9 - Cross-Site Scripting

The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS...

6.1CVSS

6.1AI Score

0.001EPSS

2023-10-05 06:36 PM
1
githubexploit
githubexploit

Exploit for Injection in Vm2 Project Vm2

CVE-2023-30547 PoC Exploit for VM2 Sandbox Escape...

10CVSS

9.6AI Score

0.002EPSS

2023-12-10 08:32 AM
479
githubexploit
githubexploit

Exploit for Incorrect Authorization in Dompdf Project Dompdf

CVE-2023-23924 Dompdf vulnerable to URI validation failure...

10CVSS

9.7AI Score

0.01EPSS

2023-02-01 06:21 PM
457
nuclei
nuclei

Aajoda Testimonials < 2.2.2 - Cross-Site Scripting

The plugin does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

4.8AI Score

0.001EPSS

2023-07-25 05:58 AM
5
wpvulndb
wpvulndb

Reviews and Rating – Google Reviews < 5.3 - Authenticated (Author+) Stored Cross-Site Scripting

Description The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated.....

6.4CVSS

5.8AI Score

0.0004EPSS

2024-05-24 12:00 AM
githubexploit
githubexploit

Exploit for Prototype Pollution in Qs Project Qs

CVE-2022-24999 This repository contain exploits samples of...

7.5CVSS

2.2AI Score

0.01EPSS

2022-04-18 06:46 AM
446
githubexploit
githubexploit

Exploit for Code Injection in Exiftool Project Exiftool

CVE-2021-22204 Summary of the CVE Improper sanitization...

7.8CVSS

7.6AI Score

0.89EPSS

2024-06-07 09:57 PM
100
githubexploit
githubexploit

Exploit for Improper Privilege Management in Sudo Project Sudo

CVE-2023-22809 sudo Privilege escalation Affected sudo...

7.8CVSS

8.2AI Score

0.001EPSS

2023-01-21 03:19 PM
464
githubexploit

10CVSS

7.3AI Score

0.003EPSS

2023-11-05 11:23 AM
756
githubexploit
githubexploit

Exploit for Improper Privilege Management in Sudo Project Sudo

CVE-2023-22809 CVE-2023-22809 is a critical...

7.8CVSS

8.3AI Score

0.001EPSS

2023-08-06 06:46 AM
155
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

pkexec-exploit Local Privilege Escalation in polkit's pkexec...

8.2AI Score

2022-01-30 10:34 AM
251
githubexploit
githubexploit

Exploit for Code Injection in Exiftool Project Exiftool

Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code...

7.8CVSS

8.5AI Score

0.89EPSS

2022-04-16 10:49 PM
427
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

CVE-2021-4034 One day for the polkit privilege escalation...

7.8CVSS

8.8AI Score

0.001EPSS

2022-01-25 11:51 PM
578
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

PwnKit Self-contained exploit for CVE-2021-4034 - Pkexec...

8.2AI Score

2022-01-26 02:26 PM
573
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

CVE-2021-4034 PoC for PwnKit: Local Privilege Escalation...

7.8CVSS

8.5AI Score

0.001EPSS

2022-01-26 12:56 AM
505
githubexploit
githubexploit

Exploit for Injection in Vm2 Project Vm2

CVE-2023-30547 vm2 is a sandbox that can run untrusted code...

10CVSS

6.8AI Score

0.002EPSS

2024-06-04 10:01 AM
161
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

CVE-2021-4034 CVE-2021-4034 Add Root User - Pkexec Local...

7.8CVSS

8.7AI Score

0.001EPSS

2022-01-28 03:13 PM
373
githubexploit
githubexploit

Exploit for Improper Preservation of Permissions in Podman Project Podman

CVE-2022-1227_Exploit A script for exploiting CVE-2022-1227....

8.8CVSS

8.8AI Score

0.002EPSS

2023-04-01 07:28 AM
473
atlassian
atlassian

Grant "Browse Project" permission to "User Custom Field Value" makes project visible to all users

{panel:bgColor=#e7f4fa} NOTE: This bug report is for JIRA Server. Using JIRA Cloud? [See the corresponding bug report|http://jira.atlassian.com/browse/JRACLOUD-37117]. {panel} If in your permission schema, you grant Browse Project permission to "User Custom Field Value", the project is visible...

6.6AI Score

2014-02-20 12:35 PM
26
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

Python3 code to exploit...

7.8CVSS

8.4AI Score

0.001EPSS

2022-01-26 05:53 PM
435
githubexploit

7.8CVSS

7.7AI Score

0.001EPSS

2023-07-10 06:38 AM
27
wpvulndb
wpvulndb

Strong Testimonials < 3.1.13 - Authenticated(Contributor+) Improper Authorization to Views Modification

Description The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor....

4.3CVSS

6.4AI Score

0.0004EPSS

2024-06-06 12:00 AM
1
githubexploit
githubexploit

Exploit for OS Command Injection in Ray Project Ray

Python POC Derived...

9.8CVSS

7AI Score

0.804EPSS

2024-04-21 02:30 PM
94
githubexploit
githubexploit

Exploit for Cross-Site Request Forgery (CSRF) in Sitemap Project Sitemap

CVE-2022-0952 Sitemap by click5 &lt; 1.0.36 - Unauthenticated...

8.8CVSS

8.8AI Score

0.453EPSS

2023-08-07 02:28 PM
171
githubexploit
githubexploit

Exploit for Injection in Glpi-Project Glpi

CVE-2022-35914 PoC References ...

9.8CVSS

7.9AI Score

0.974EPSS

2024-04-24 06:39 AM
226
githubexploit
githubexploit

Exploit for Injection in Glpi-Project Glpi

Exploit Script Utility...

9.8CVSS

8.2AI Score

0.974EPSS

2024-05-29 07:54 PM
77
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

PwnKit-Exploit CVE-2021-4034 ...

8.1AI Score

2022-01-26 06:01 PM
363
osv
osv

Malicious code in eslint-plugin-cdp-project (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 12:41 PM
githubexploit
githubexploit

Exploit for Uncontrolled Resource Consumption in Quic-Go Project Quic-Go

QUIC-attacks (CVE-2022-30591) The current repository serves...

7.5AI Score

2022-06-30 06:25 PM
441
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

CVE-2021-4034 CVE-2021-4034 centos8可用版本...

7.8CVSS

8.6AI Score

0.001EPSS

2022-02-15 02:34 AM
325
githubexploit
githubexploit

Exploit for Off-by-one Error in Sudo Project Sudo

PE_CVE-CVE-2021-3156 Exploit for Ubuntu 20.04 using...

7.8CVSS

8.6AI Score

0.97EPSS

2023-05-13 01:02 AM
225
cve
cve

CVE-2023-6884

This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with...

6.4CVSS

5AI Score

0.0005EPSS

2024-02-05 10:15 PM
18
githubexploit
githubexploit

Exploit for Improper Check for Unusual or Exceptional Conditions in Polkit Project Polkit

Description As part of my cybersecurity thesis I wanted to...

7.8CVSS

8.3AI Score

0.012EPSS

2024-03-24 11:37 AM
164
freebsd
freebsd

kanboard -- Project Takeover via IDOR in ProjectPermissionController

[email protected] reports: Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL...

8.2CVSS

8AI Score

0.0004EPSS

2024-06-06 12:00 AM
6
wpexploit
wpexploit

Site Reviews < 7.0.0 - IP Spoofing

Description The plugin retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based...

6.7AI Score

0.0004EPSS

2024-05-08 12:00 AM
16
githubexploit

8.2AI Score

2022-02-13 12:05 AM
471
githubexploit
githubexploit

Exploit for Improper Check for Unusual or Exceptional Conditions in Polkit Project Polkit

PolicyKit CVE-2021-3560 Exploit (Authentication Agent)...

7.8CVSS

7.3AI Score

0.012EPSS

2022-04-29 06:57 PM
170
osv
osv

CVE-2024-37167

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-06-25 08:15 PM
1
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

██████╗ ██╗ ██╗██╗ ██╗███╗ ██╗███████╗██████╗ ██╔══██...

8AI Score

2022-01-26 08:43 AM
241
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

CVE-2021-4034 Precompiled builds for CVE-2021-4034. Of...

7.8CVSS

8.5AI Score

0.001EPSS

2022-01-27 05:43 PM
293
githubexploit
githubexploit

Exploit for Server-Side Request Forgery in Fusion Builder Project Fusion Builder

Fubucker | CVE-2022-1386 - Fusion Builder Automatic Mass Tool...

9.6AI Score

2023-03-05 01:46 AM
364
githubexploit
githubexploit

Exploit for Off-by-one Error in Sudo Project Sudo

CVE-2021-3156 [toc] 漏洞简介 漏洞编号: CVE-2021-3156...

7.8CVSS

7.9AI Score

0.97EPSS

2022-01-27 02:31 AM
279
nuclei
nuclei

Art Gallery Management System Project v1.0 - Cross-Site Scripting

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation...

6.1CVSS

5.9AI Score

0.003EPSS

2023-07-22 06:07 AM
7
wpvulndb
wpvulndb

Builder for WooCommerce reviews shortcodes – ReviewShort < 1.01.6 - Missing Authorization

Description The Builder for WooCommerce reviews shortcodes – ReviewShort plugin for WordPress is vulnerable to unauthorized access of functionality in versions up to, and including, 1.01.5. This makes it possible for unauthenticated attackers to make use of this functionality intended for higher...

5.3CVSS

6.7AI Score

0.0004EPSS

2024-05-20 12:00 AM
3
osv
osv

Argo CD's API server does not enforce project sourceNamespaces

Impact I can convince the UI to let me do things with an invalid Application. 1. Admin gives me p, michael, applications, , demo/ , allow, where demo can just deploy to the demo namespace 2. Admin gives me AppProject dev which reconciles from ns dev-apps 3. Admin gives me p, michael,...

4.8CVSS

5AI Score

0.0004EPSS

2024-04-15 08:20 PM
7
nuclei
nuclei

Enrollment System Project v1.0 - SQL Injection Authentication Bypass

Enrollment System Project V1.0, developed by Sourcecodester, has been found to be vulnerable to SQL Injection (SQLI) attacks. This vulnerability allows an attacker to manipulate the SQL queries executed by the application. The system fails to properly validate user-supplied input in the username...

9.8CVSS

10AI Score

0.006EPSS

2023-10-17 07:20 AM
24
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

CVE-2021-4034-PwnKit PwnKit PoC for Polkit pkexec...

7.8CVSS

8.6AI Score

0.001EPSS

2022-01-30 03:08 AM
182
githubexploit
githubexploit

Exploit for Code Injection in Exiftool Project Exiftool

CVE-2021-22204 Exploit for CVE-2021-22204 (ExifTool) -...

7.8CVSS

8.2AI Score

0.89EPSS

2023-05-14 03:43 AM
179
Total number of security vulnerabilities104241