Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 14701-14720 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-28612 - Custom Popup Builder Plugin

Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin

PLUGIN Custom Popup Builder

CVE-2022-28612

MEDIUM CVSS 5.4 2022-06-15
Threat Entry Updated 2024-11-21

CVE-2022-27859 - Nd Travel Plugin

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin

PLUGIN Nd Travel

CVE-2022-27859

MEDIUM CVSS 4.1 2022-06-15
Threat Entry Updated 2024-11-21

CVE-2022-1768 - Rsvpmaker Plugin

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

PLUGIN Rsvpmaker

CVE-2022-1768

CRITICAL CVSS 9.8 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1969 - Mobile Browser Color Select Plugin

The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Mobile Browser Color Select

CVE-2022-1969

HIGH CVSS 8.8 2022-06-13
Threat Entry Updated 2025-05-05

CVE-2022-1749 - Find Any Think Plugin

The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

PLUGIN Find Any Think

CVE-2022-1749

HIGH CVSS 8.8 2022-06-13
Scroll to top