Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2022
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-17
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-17
Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-11-17
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
CVSS Score
6.3
EPSS Score
0.002
Published
2022-11-17
Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
CVSS Score
6.3
EPSS Score
0.002
Published
2022-11-17
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in iFeature Slider plugin <= 1.2 on WordPress.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-11-17
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-11-17
In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239415718References: N/A
CVSS Score
7.8
EPSS Score
0.0
Published
2022-11-17
Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.
CVSS Score
6.8
EPSS Score
0.001
Published
2022-11-17
A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-11-17


Contact Us

Shodan ® - All rights reserved