Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ajax vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-0694
The Advanced Booking Calendar WordPress plugin prior to 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauth...
Elbtide Advanced Booking Calendar
9.8
CVSSv3
CVE-2022-0739
The BookingPress WordPress plugin prior to 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthent...
Reputeinfosystems Bookingpress
8 Github repositories
9.8
CVSSv3
CVE-2022-0747
The Infographic Maker WordPress plugin prior to 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
Quantumcloud Infographic Maker
9.8
CVSSv3
CVE-2022-25498
CuppaCMS v1.0 exists to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
Cuppacms Cuppacms 1.0
9.8
CVSSv3
CVE-2022-25488
Atom CMS v2.0 exists to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
Thedigitalcraft Atomcms 2.0
9.8
CVSSv3
CVE-2022-0658
The CommonsBooking WordPress plugin prior to 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection
Wielebenwir Commonsbooking
9.8
CVSSv3
CVE-2022-0169
The Photo Gallery by 10Web WordPress plugin prior to 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthe...
10web Photo Gallery
9.8
CVSSv3
CVE-2021-24762
The Perfect Survey WordPress plugin prior to 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
Getperfectsurvey Perfect Survey
1 Github repository
9.8
CVSSv3
CVE-2021-41472
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows malicious users to execute arbitrary SQL commands via the username and password parameters.
Simple Membership System Using Php And Ajax Project Simple Membership System Using Php And Ajax 1.0
9.8
CVSSv3
CVE-2021-44029
An issue exists in Quest KACE Desktop Authority prior to 11.2. This vulnerability allows malicious users to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption k...
Quest Kace Desktop Authority
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »