Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | SearchWP Live Ajax Search | 1.6.2 ~ 1.6.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The plugin does not ensure that users making. alive search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2535.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-2116 | Elementor Contact Form DB < 1.8.0 - Reflected Cross-Site Scripting | |
| CVE-2022-2152 | Duplicate Page and Post Plugin < 2.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2180 | GREYD.SUITE < 1.2.7 - Unauthenticated File Upload to RCE | |
| CVE-2022-2314 | VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call | |
| CVE-2022-2354 | WP-DBManager < 2.80.8 - Admin+ Remote Command Execution | |
| CVE-2022-2378 | Easy Student Results <= 2.2.8 - Reflected Cross-Site Scripting | |
| CVE-2022-2379 | Easy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST API | |
| CVE-2022-2381 | E Unlocked - Student Result <= 1.0.4 - Arbitrary File Upload via CSRF | |
| CVE-2022-2384 | Digital Publications by Supsystic < 1.7.4 - Admin+ Stored Cross-Site Scripting |
No comments yet