Skip to main content

CWE archive

CWE-348 CVEs

Programmatic archive

65 CVEs tagged with CWE-3488 Critical, 16 High, 33 Medium, 8 Low, 0 Unrated.

CVE-2022-4529

Published Sep 5, 2024

The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due to insufficient restrictio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4539

Published Aug 31, 2024

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4536

Published Aug 31, 2024

The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the I…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4532

Published Aug 17, 2024

The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due to insufficient restrictions…

CVSS 6.5 · Medium

CVE-2022-44593

Published Jun 21, 2024

Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0789

Published Jun 19, 2024

The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of use…

CVSS 5.3 · Medium

CVE-2024-23105

Published May 14, 2024

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2897

Published Jun 9, 2023

The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP add…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4537

Published May 9, 2023

The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21374

Published Mar 26, 2021

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTT…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21373

Published Mar 26, 2021

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 51-65 of 65 CVEsPage 3 of 3