Перейти к содержимому
Noroxi

Записи properfraction

35 опубликованных записей вендора properfraction.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
42,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

35 записей
  • CVE-2021-34621
    60На этой неделе

    ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

    КритическаяCVSS 9,8Proof of conceptEPSS 69 %

    properfraction · profilepress7 июл. 2021 г.

  • CVE-2021-34624
    41В плане

    ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    properfraction · profilepress7 июл. 2021 г.

  • CVE-2021-34623
    40В плане

    ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    properfraction · profilepress7 июл. 2021 г.

  • CVE-2024-9947
    39Наблюдать

    ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    properfraction · profilepress23 окт. 2024 г.

  • CVE-2021-34622
    36Наблюдать

    ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation

    ВысокаяCVSS 8,8Proof of conceptEPSS 4 %

    properfraction · profilepress7 июл. 2021 г.

  • CVE-2023-41954
    34Наблюдать

    WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability

    ВысокаяCVSS 8,6Proof of conceptEPSS 1 %

    properfraction · profilepress17 мая 2024 г.

  • CVE-2023-44150
    30Наблюдать

    WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    properfraction · profilepress30 нояб. 2023 г.

  • CVE-2022-45083
    28Наблюдать

    WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    properfraction · profilepress19 янв. 2024 г.

  • CVE-2021-24522
    24Наблюдать

    ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    properfraction · profilepress9 авг. 2021 г.

  • CVE-2024-1519
    24Наблюдать

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    properfraction · profilepress28 февр. 2024 г.

  • CVE-2023-23830
    24Наблюдать

    WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    properfraction · profilepress3 мая 2023 г.

  • CVE-2022-47444
    24Наблюдать

    WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    properfraction · profilepress29 мар. 2023 г.

  • CVE-2024-1408
    21Наблюдать

    ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    properfraction · profilepress28 февр. 2024 г.

  • CVE-2024-1535
    21Наблюдать

    ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    properfraction · profilepress13 мар. 2024 г.

  • CVE-2024-1806
    21Наблюдать

    ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    properfraction · profilepress13 мар. 2024 г.

  • CVE-2023-50882
    21Наблюдать

    WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    properfraction · profilepress9 дек. 2024 г.

  • CVE-2024-1570
    21Наблюдать

    ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress28 февр. 2024 г.

  • CVE-2024-1409
    21Наблюдать

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress13 мар. 2024 г.

  • CVE-2024-3210
    21Наблюдать

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress10 апр. 2024 г.

  • CVE-2023-41953
    21Наблюдать

    WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    properfraction · profilepress9 дек. 2024 г.

  • CVE-2023-23820
    21Наблюдать

    WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress3 мая 2023 г.

  • CVE-2024-11083
    21Наблюдать

    ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    properfraction · profilepress27 нояб. 2024 г.

  • CVE-2024-2867
    21Наблюдать

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress2 мая 2024 г.

  • CVE-2024-1046
    21Наблюдать

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress5 февр. 2024 г.

  • CVE-2024-2861
    21Наблюдать

    ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    properfraction · profilepress23 мая 2024 г.