Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-43470 +1 in the same advisory: …43442 | Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W sof Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W software versions v3.3.5 and earlier, and +F FS040W software versions v1.4.1 and earlier allows an adjacent attacker to hijack the authentication of an administrator and user's unintended operations such as to reboot the product and/or reset the configuration to the initial set-up may be performed. NVD description · AI analysis pending | 7.3 group max | <1% |
| — | ||
| CVE-2016-11005 | The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS. The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2018-14012 | WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI. WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-0520 +1 in the same advisory: …0519 | Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrator Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors. NVD description · AI analysis pending | 8.8 group max | <1% |
| — |