Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2022
D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-12-20
The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-12-20
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CVSS Score
9.8
EPSS Score
0.846
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the urls parameter at /goform/saveParentControlInfo.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the time parameter at /goform/saveParentControlInfo.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceMac parameter at /goform/addWifiMacFilter.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeed parameter at /goform/SetClientState.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the speed_dir parameter at /goform/SetSpeedWan.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/SetClientState.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeedUp parameter at /goform/SetClientState.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-20


Contact Us

Shodan ® - All rights reserved