Latest CVE Feed
-
4.0
MEDIUMCVE-2022-1686
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection... Read more
Affected Products : five_minute_webshop- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2022-1685
The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection... Read more
Affected Products : five_minute_webshop- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2022-1684
The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin... Read more
Affected Products : cube_slider- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1683
The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement via its shortcode, leading to an SQL injection and is exploitable by any authenticated user (and not just Author+ like the original ad... Read more
Affected Products : amtythumb- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1682
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser... Read more
Affected Products : facturascripts- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2022-1681
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions... Read more
Affected Products : wiki.js- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-1680
An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCI... Read more
Affected Products : gitlab- Published: Jun. 06, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1679
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their pr... Read more
Affected Products : linux_kernel debian_linux h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s +8 more products- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1678
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.... Read more
Affected Products : linux_kernel active_iq_unified_manager h410c_firmware hci_management_node solidfire e-series_santricity_os_controller element_software h300s_firmware h500s_firmware h700s_firmware +16 more products- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-1677
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or ... Read more
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-1674
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application cr... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1673
The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter before outputting it to the page, leading to a Reflected Cross-Site Scripting vulnerability.... Read more
Affected Products : woocommerce_green_wallet_gateway- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1672
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks... Read more
Affected Products : insights_from_google_pagespeed- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-1671
A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.... Read more
Affected Products : linux_kernel h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s h700s +1 more products- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1670
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.... Read more
Affected Products : octopus_server- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-1669
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a... Read more
- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-1668
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1667
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1666
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2022-1665
A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can by... Read more
Affected Products : enterprise_linux- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024