Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2024-1037
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter i…
All In One Security
5.2.6+
MEDIUM 5.4
CVE-2023-5982
The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl…
Updraftplus
after 1.23.10
MEDIUM 6.1
CVE-2023-26530
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.
Updraft
after 0.6.1
MEDIUM 6.1
CVE-2023-32960
Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sit…
Updraftplus
after 1.23.3
MEDIUM 5.3
CVE-2022-4346
The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.
All In One Security
5.1.3+
MEDIUM 5.3
CVE-2022-4097
The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (lik…
All In One Security
5.0.8+
MEDIUM 6.1
CVE-2022-0864EPSS 7%
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting …
Updraftplus
1.22.9+
MEDIUM 6.5
CVE-2022-0633
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a…
Updraftplus
1.22.3 / 2.22.3+
MEDIUM 6.1
CVE-2021-25089
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting …
Updraftplus
1.16.69+
MEDIUM 6.1
CVE-2021-25022
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before…
Updraftplus
1.16.66+
MEDIUM 6.1
CVE-2017-18593
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
Updraftplus
1.13.5+
MEDIUM 6.1
CVE-2015-9360
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
Updraftplus
1.9.64+
HIGH 8.1
CVE-2017-16870
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via a…
Updraftplus
after 1.13.12
HIGH 8.1
CVE-2017-16871
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd…
Updraftplus
after 1.13.12