Latest CVE Feed
-
6.5
MEDIUMCVE-2022-1936
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token t... Read more
Affected Products : gitlab- Published: Jun. 06, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1935
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token ... Read more
Affected Products : gitlab- Published: Jun. 06, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1934
Use After Free in GitHub repository mruby/mruby prior to 3.2.... Read more
Affected Products : mruby- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1933
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting... Read more
Affected Products : collect_and_deliver_interface_for_woocommerce- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1932
The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct ca... Read more
Affected Products : rezgo_online_booking- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-1931
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.... Read more
Affected Products : trudesk- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1930
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method... Read more
Affected Products : eth-account- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1929
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method... Read more
Affected Products : devcert- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1928
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.... Read more
Affected Products : gitea- Published: May. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1927
Buffer Over-read in GitHub repository vim/vim prior to 8.2.... Read more
- Published: May. 29, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-1926
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.... Read more
Affected Products : trudesk- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1925
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux elemen... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1924
DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used,... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1923
DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc use... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1922
DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on th... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1921
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1920
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1919
Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1918
The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it possible for unauthenticated attackers ... Read more
Affected Products : toolbar_to_share- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1916
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenti... Read more
Affected Products : woot- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024