Latest CVE Feed
-
8.4
HIGHCVE-2022-1754
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.... Read more
Affected Products : trudesk- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1753
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible t... Read more
Affected Products : wowonder- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2022-1752
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.... Read more
Affected Products : trudesk- Published: May. 21, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1748
Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.... Read more
Affected Products : opc secure_integration_server edgeconnector uagates edgeaggregator opc_ua_c\+\+_software_development_kit- Published: Aug. 17, 2022
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2022-1738
Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to leak sensitive data from the process memory.... Read more
Affected Products : d300win- Published: Oct. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1737
Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a de... Read more
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1735
Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.... Read more
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2022-1734
A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.... Read more
Affected Products : linux_kernel debian_linux h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s +8 more products- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1733
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.... Read more
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1732
The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : rename_wp-login- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1731
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.... Read more
Affected Products : metasonic_doc_webclient- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-1730
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.... Read more
Affected Products : drawio- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2022-1729
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.... Read more
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-1728
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.... Read more
Affected Products : trudesk- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1727
Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.... Read more
Affected Products : drawio- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-1726
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-par... Read more
Affected Products : bootstrap_table- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-1725
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.... Read more
- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1724
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting... Read more
Affected Products : simple_membership- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1723
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.... Read more
Affected Products : drawio- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1722
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses... Read more
Affected Products : drawio- Published: May. 16, 2022
- Modified: Nov. 21, 2024