Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2024
Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.
CVSS Score
9.9
EPSS Score
0.006
Published
2024-01-08
Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.
CVSS Score
10.0
EPSS Score
0.008
Published
2024-01-08
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce: from n/a through 1.5.1.
CVSS Score
9.3
EPSS Score
0.003
Published
2024-01-08
Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.
CVSS Score
10.0
EPSS Score
0.008
Published
2024-01-08
io_uring UAF, Unix SCM garbage collection
CVSS Score
5.3
EPSS Score
0.013
Published
2024-01-08
Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVSS Score
7.8
EPSS Score
0.001
Published
2024-01-08
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
CVSS Score
5.3
EPSS Score
0.004
Published
2024-01-08
CVE-2022-2586
Known exploited
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVSS Score
5.3
EPSS Score
0.022
Published
2024-01-08
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
CVSS Score
5.3
EPSS Score
0.543
Published
2024-01-08
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue affects WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting: from n/a through 1.12.8.
CVSS Score
7.6
EPSS Score
0.003
Published
2024-01-08


Contact Us

Shodan ® - All rights reserved