Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-13609 +1 in the same advisory: …13555 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process. NVD description · AI analysis pending | 5.9 group max | 2% |
| — | ||
| CVE-2020-23911 +1 in the same advisory: …23910 | An issue was discovered in asn1c through v0.9.28. An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in asn1fix.c. It allows an attacker to cause Denial of Service. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2020-18460 | Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content. Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2021-32616 | 1CDN is open-source file sharing software. 1CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a basic cross-site scripting vulnerability that allows an attacker to inject / and execute JavaScript code on the client side. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-3131 | The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter. The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-15958 | An issue was discovered in 1CRM System through 8.6.7. An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL. NVD description · AI analysis pending | 8.6 | 3% | PoC ×2 |
| — | |
| CVE-2019-14221 | 1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. 1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. NVD description · AI analysis pending | 5.4 | 2% | PoC ×2 |
| — | |
| CVE-2017-12966 | The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation f The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted .asn1 file. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — |