The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
CVE-2022-1023
Podcast Importer SecondLine
Web
Database
Windows
N/A
UNKNOWN
EPSS
0.6%
CVE-2022-26613
Software Genérico
Web
Database
N/A
UNKNOWN
EPSS
0.3%
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
CVE-2022-1692
CP Image Store with Slideshow
Web
Database
Windows
⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack
CVE-2022-35115
Software Genérico
Web
Database
N/A
UNKNOWN
EPSS
0.7%
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
CVE-2022-27444
Software Genérico
Database
N/A
UNKNOWN
EPSS
0.1%
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.
← Anterior
Página 52 de 52