Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,313
Critical1,021
High3,386
Medium11,660
Reset
Showing 14221-14240 of 16313 records
Threat Entry Updated 2024-11-21

CVE-2022-2937 - Image Hover Effects Ultimate Plugin

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to…

PLUGIN Image Hover Effects Ultimate

CVE-2022-2937

MEDIUM CVSS 6.4 2022-09-23
Threat Entry Updated 2024-11-21

CVE-2022-3144 - Wordfence Plugin

The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.

PLUGIN Wordfence

CVE-2022-3144

MEDIUM CVSS 4.4 2022-09-23
Threat Entry Updated 2024-11-21

CVE-2022-2840 - Zephyr Project Manager Plugin

The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections

PLUGIN Zephyr Project Manager

CVE-2022-2840

CRITICAL CVSS 9.8 2022-09-19
Threat Entry Updated 2024-11-21

CVE-2022-3142 - Before 7 Plugin

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

PLUGIN Before 7

CVE-2022-3142

HIGH CVSS 8.8 2022-09-19
Scroll to top