CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2023-01-11
N/A
6.5 MEDIUM
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-12-03
N/A
5.5 MEDIUM
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-06-29
N/A
6.5 MEDIUM
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.
Location_weather, Logo_carousel, Post_grid,_post_carousel,_&_list_category_posts, Product_slider_for_woocommerce, Real_testimonials, Wp_tabs
2022-08-25
N/A
4.3 MEDIUM
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.
The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment.
