Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.2

    HIGH
    CVE-2022-1824

    An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissi... Read more

    Affected Products : consumer_product_removal_tool
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
  • 7.9

    HIGH
    CVE-2022-1823

    Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining ... Read more

    Affected Products : consumer_product_removal_tool
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2022-1821

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the me... Read more

    Affected Products : gitlab
    • Published: Jun. 06, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-1820

    The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated... Read more

    Affected Products : keep_backup_daily
    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-1819

    A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross site scr... Read more

    Affected Products : student_information_system
    • Published: May. 24, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-1818

    The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack o... Read more

    Affected Products : multi-page_toolkit
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-1817

    A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="aler... Read more

    • Published: May. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-1816

    A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the in... Read more

    Affected Products : zoo_management_system
    • Published: May. 23, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-1815

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.... Read more

    Affected Products : drawio
    • Published: May. 25, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-1814

    The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed... Read more

    Affected Products : wp_admin_style
    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-1813

    OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.... Read more

    Affected Products : rengine
    • Published: May. 22, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-1812

    Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.... Read more

    Affected Products : publify
    • Published: Jan. 14, 2023
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-1811

    Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.... Read more

    Affected Products : publify
    • Published: May. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2022-1810

    Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.... Read more

    Affected Products : publify
    • Published: May. 23, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1809

    Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.... Read more

    Affected Products : radare2
    • Published: May. 21, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-1808

    Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.... Read more

    Affected Products : trudesk
    • Published: May. 31, 2022
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2022-1806

    Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.... Read more

    Affected Products : rtx
    • Published: May. 20, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2022-1805

    When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provi... Read more

    • Published: Jul. 28, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-1803

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.... Read more

    Affected Products : trudesk
    • Published: May. 20, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-1801

    The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the ... Read more

    Affected Products : very_simple_contact_form
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294633 Results