Latest CVE Feed
-
4.8
MEDIUMCVE-2022-1819
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross site scr... Read more
Affected Products : student_information_system- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1818
The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack o... Read more
Affected Products : multi-page_toolkit- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1817
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="aler... Read more
Affected Products : badminton_center_management_system- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1816
A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the in... Read more
Affected Products : zoo_management_system- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1815
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.... Read more
Affected Products : drawio- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1814
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed... Read more
Affected Products : wp_admin_style- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1813
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.... Read more
Affected Products : rengine- Published: May. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1812
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.... Read more
Affected Products : publify- Published: Jan. 14, 2023
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-1811
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.... Read more
Affected Products : publify- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-1810
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.... Read more
Affected Products : publify- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1809
Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.... Read more
Affected Products : radare2- Published: May. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1808
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.... Read more
Affected Products : trudesk- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-1806
Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.... Read more
Affected Products : rtx- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-1805
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provi... Read more
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2022-1803
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.... Read more
Affected Products : trudesk- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1801
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the ... Read more
Affected Products : very_simple_contact_form- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-1800
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.... Read more
Affected Products : export_any_wordpress_data_to_xml\/csv- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1799
Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.... Read more
Affected Products : google_play_services_software_development_kit- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2022-1798
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 1... Read more
Affected Products : kubevirt- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2022-1797
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user w... Read more
Affected Products : compactlogix_5380_firmware controllogix_5580_firmware compact_guardlogix_5380_firmware compactlogix_5480_firmware guardlogix_5580_firmware compactlogix_5370_firmware compact_guardlogix_5370_firmware controllogix_5570_firmware guardlogix_5570_firmware compactlogix_5380 +8 more products- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024