高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Unknown | ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | 3.4.8 ~ 3.4.8 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|---|---|---|
| 1 | ARMember < 3.4.8 - Unauthenticated Admin Account Takeover | https://github.com/biulove0x/CVE-2022-1903 | POC詳細 |
| 2 | The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1903.yaml | POC詳細 |
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2022-1953 | Product Configurator for WooCommerce < 1.2.32 - Unauthenticated Arbitrary File Deletion | |
| CVE-2022-1844 | WP Sentry <= 1.0 - Arbitrary Settings Update to Stored XSS via CSRF | |
| CVE-2022-1845 | WP Post Styling < 1.3.1 - Multiple CSRF | |
| CVE-2022-1846 | Tiny Contact Form <= 0.7 - Arbitrary Settings Update via CSRF | |
| CVE-2022-1847 | Rotating Posts <= 1.11 - Arbitrary Settings Update to Stored XSS via CSRF | |
| CVE-2022-1885 | Cimy Header Image Rotator <= 6.1.1 - Arbitrary Settings Update via CSRF | |
| CVE-2022-1904 | Easy Pricing Tables < 3.2.1 - Reflected Cross-Site-Scripting | |
| CVE-2022-1913 | Add Post URL <= 2.1.0 - Arbitrary Settings Update to Stored XSS via CSRF | |
| CVE-2022-1914 | Clean-Contact <= 1.6 - Arbitrary Settings Update to Stored XSS via CSRF | |
| CVE-2022-1916 | Active Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-Scripting | |
| CVE-2022-1843 | MailPress <= 7.2.1 - Arbitrary Settings Update & Log Files Purge via CSRF | |
| CVE-2022-1960 | MyCSS <= 1.1 - Arbitrary Settings Update via CSRF | |
| CVE-2022-1964 | Easy SVG Support < 3.3.0 - Author+ Stored Cross Site Scripting via SVG | |
| CVE-2022-1971 | NextCellent Gallery <= 1.9.35 - Admin+ Stored XSS | |
| CVE-2022-1977 | WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF | |
| CVE-2022-1990 | Nested Pages < 3.1.21 - Admin+ Stored Cross Site Scripting | |
| CVE-2022-1994 | Google Authenticator < 1.0.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1995 | miniOrange's Malware Scanner < 4.5.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2040 | Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element URL | |
| CVE-2022-2041 | Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element Content |
Showing 20 of 41 CVEs. View all on vendor page →
まだコメントはありません