CVE-2022-40089

CRITICAL Year: 2022
CVSS v3 Score
9.8
Critical

Vulnerability Description

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

CVSS:9.8(Critical)

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file ...

CWE-982014
CVSS:9.8(Critical)

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CWE-982022
CVSS:9.8(Critical)

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unau...

CWE-982024
CVSS:9.8(Critical)

The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-post-layout]' parameter. This makes it possible for ...

CWE-982024
CVSS:9.8(Critical)

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrell...

CWE-982024
CVSS:9.8(Critical)

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for ...

CWE-982024