Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-1815

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.... Read more

    Affected Products : drawio
    • Published: May. 25, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-1814

    The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed... Read more

    Affected Products : wp_admin_style
    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-1813

    OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.... Read more

    Affected Products : rengine
    • Published: May. 22, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-1812

    Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.... Read more

    Affected Products : publify
    • Published: Jan. 14, 2023
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-1811

    Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.... Read more

    Affected Products : publify
    • Published: May. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2022-1810

    Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.... Read more

    Affected Products : publify
    • Published: May. 23, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1809

    Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.... Read more

    Affected Products : radare2
    • Published: May. 21, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-1808

    Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.... Read more

    Affected Products : trudesk
    • Published: May. 31, 2022
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2022-1806

    Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.... Read more

    Affected Products : rtx
    • Published: May. 20, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2022-1805

    When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provi... Read more

    • Published: Jul. 28, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-1803

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.... Read more

    Affected Products : trudesk
    • Published: May. 20, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-1801

    The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the ... Read more

    Affected Products : very_simple_contact_form
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-1800

    The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.... Read more

    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-1799

    Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.... Read more

    • Published: Jul. 29, 2022
    • Modified: Nov. 21, 2024
  • 8.7

    HIGH
    CVE-2022-1798

    A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 1... Read more

    Affected Products : kubevirt
    • Published: Sep. 15, 2022
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2022-1797

    A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user w... Read more

    • Published: Jun. 02, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1796

    Use After Free in GitHub repository vim/vim prior to 8.2.4979.... Read more

    Affected Products : vim
    • Published: May. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-1795

    Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.... Read more

    Affected Products : gpac
    • Published: May. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-1794

    The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.... Read more

    Affected Products : windows opc_da_server
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2022-1793

    The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public... Read more

    Affected Products : private_files
    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294836 Results