Latest CVE Feed
-
6.5
MEDIUMCVE-2022-1831
The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : wplite- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1830
The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the... Read more
Affected Products : amazon_einzeltitellinks- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1829
The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack... Read more
Affected Products : inline_google_maps- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1828
The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : pdf24_articles_to_pdf- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1827
The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : pdf24_articles_to_pdf- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1826
The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which could allow attackers to make a logged in admin perform such action via a CSRF attack... Read more
Affected Products : cross-linker- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1825
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.... Read more
Affected Products : providence- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2022-1824
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissi... Read more
Affected Products : consumer_product_removal_tool- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
7.9
HIGHCVE-2022-1823
Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining ... Read more
Affected Products : consumer_product_removal_tool- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1821
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the me... Read more
Affected Products : gitlab- Published: Jun. 06, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1820
The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated... Read more
Affected Products : keep_backup_daily- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1819
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross site scr... Read more
Affected Products : student_information_system- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1818
The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack o... Read more
Affected Products : multi-page_toolkit- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1817
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="aler... Read more
Affected Products : badminton_center_management_system- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1816
A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the in... Read more
Affected Products : zoo_management_system- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1815
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.... Read more
Affected Products : drawio- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1814
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed... Read more
Affected Products : wp_admin_style- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1813
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.... Read more
Affected Products : rengine- Published: May. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1812
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.... Read more
Affected Products : publify- Published: Jan. 14, 2023
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-1811
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.... Read more
Affected Products : publify- Published: May. 23, 2022
- Modified: Nov. 21, 2024