CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2022-33932

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotected primary channel vulnerability. An unauthenticated network malicious attacker may potentially exploit this vulnerability, leading to a denial of filesystem services.

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-32480

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulnerability, leading to information disclosure.

    Published: 22 Aug 2022
    4.7
    Medium

    CVE-2022-31238

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this vulnerability, leading to information disclosure.

    Published: 22 Aug 2022
    3.3
    Low

    CVE-2022-31237

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure.

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-35150

    Last Modified: 21 Nov 2024

    Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2022-2600

    Last Modified: 21 Nov 2024

    The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2021-3484

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    8.8
    High

    CVE-2022-2594

    Last Modified: 21 Nov 2024

    The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36276

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    7.2
    High

    CVE-2022-2593

    Last Modified: 21 Nov 2024

    The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36275

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    5.3
    Medium

    CVE-2022-2558

    Last Modified: 21 Nov 2024

    The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certain configurations.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36274

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    8.8
    High

    CVE-2022-2557

    Last Modified: 21 Nov 2024

    The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36273

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36272

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    6.5
    Medium

    CVE-2022-2555

    Last Modified: 21 Nov 2024

    The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.

    Published: 22 Aug 2022
    5.3
    Medium

    CVE-2022-2552

    Last Modified: 2 Feb 2026

    The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36271

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36270

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    7.5
    High

    CVE-2022-2551

    Last Modified: 2 Feb 2026

    The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36269

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    7.5
    High

    CVE-2022-2544

    Last Modified: 21 Nov 2024

    The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36268

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-2532

    Last Modified: 21 Nov 2024

    The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36267

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    4.8
    Medium

    CVE-2022-2407

    Last Modified: 21 Nov 2024

    The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36266

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    6.5
    Medium

    CVE-2022-2392

    Last Modified: 21 Nov 2024

    The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36265

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-2389

    Last Modified: 21 Nov 2024

    The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36264

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36263

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    6.5
    Medium

    CVE-2022-2388

    Last Modified: 21 Nov 2024

    The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36262

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-2383

    Last Modified: 21 Nov 2024

    The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-2382

    Last Modified: 21 Nov 2024

    The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36261

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-2377

    Last Modified: 21 Nov 2024

    The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36260

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2022-2375

    Last Modified: 21 Nov 2024

    The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36259

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    7.5
    High

    CVE-2022-2362

    Last Modified: 21 Mar 2025

    The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36258

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2020-36257

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Aug 2022
    4.8
    Medium

    CVE-2022-2361

    Last Modified: 21 Nov 2024

    The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2022-2312

    Last Modified: 21 Nov 2024

    The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-2276

    Last Modified: 21 Nov 2024

    The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-2275

    Last Modified: 21 Nov 2024

    The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-2198

    Last Modified: 21 Nov 2024

    The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.

    Published: 22 Aug 2022