High · CVSS 8.8
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 5.3
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 5.4
The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 6.1
The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 4.3
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.5
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 4.8
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.8
off-by-one in io_uring module.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 6.5
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 6.5
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 4.3
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 6.5
Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.8
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
Published Sep 26, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.
Published Sep 26, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.
Published Sep 26, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.
Published Sep 26, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
Published Sep 26, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.
Published Sep 26, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.
Published Sep 27, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.
Published Sep 27, 2022 · Updated May 21, 2025
Medium · CVSS 5.4
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.
Published Sep 27, 2022 · Updated May 21, 2025
Low · CVSS 2.7
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure information.
Published Sep 27, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.
Published Sep 23, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.
Published Sep 23, 2022 · Updated May 21, 2025
Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.
Published Sep 23, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 8.8
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 6.5
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.
Published Sep 26, 2022 · Updated May 21, 2025