Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

CVE-2023-27315: CVE-2023-27315 Information Disclosure Vulnerability in SnapGathers

SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials

CVE
#vulnerability#auth
Backdoor Lurks Behind WordPress Caching Plug-in to Hijack Websites

Evasive malware disguised as a caching plug-in allows attackers to create an admin account on a WordPress site, then take over and monetize sites at the expense of legitimate SEO and user privacy.

Dawa Pharma 1.0-2022 SQL Injection

Dawa Pharma version 1.0-2022 suffers from a remote SQL injection vulnerability.

Lost And Found Information System 1.0 Insecure Direct Object Reference

Lost and Found Information System version 1.0 suffers from an insecure direct object reference vulnerability that allows for account takeover.

Clinic's Patient Management System 1.0 Shell Upload

Clinic's Patient Management System version 1.0 suffers from a remote shell upload vulnerability.

CVE-2023-45068: WordPress Contact Form by Supsystic plugin <= 1.7.27 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Contact Form by Supsystic plugin <= 1.7.27 versions.

CVE-2023-45048: WordPress Social proof testimonials and reviews by Repuso plugin <= 5.00 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Repuso Social proof testimonials and reviews by Repuso plugin <= 5.00 versions.

CVE-2023-44998: WordPress Category Meta plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in josecoelho, Randy Hoyt, steveclarkcouk, Vitaliy Kukin, Eric Le Bail, Tom Ransom Category Meta plugin plugin <= 1.2.8 versions.

CVE-2023-45011: WordPress WP Power Stats plugin <= 2.2.3 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Igor Buyanov WP Power Stats plugin <= 2.2.3 versions.