Latest CVE Feed
-
4.8
MEDIUMCVE-2022-1266
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : post_grid\,_slider_\&_carousel_ultimate- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1265
The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : bulletproof_security- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1264
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.... Read more
Affected Products : ignition- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1263
A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1262
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.... Read more
Affected Products : dir-867_firmware dir-878_firmware dir-3040_firmware dir-3060_firmware dir-882_firmware dir-1960_firmware dir-1360_firmware dir-1760_firmware dir-2640_firmware dir-2660_firmware +10 more products- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2022-1261
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-l... Read more
Affected Products : matrikon_opc_server- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1259
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2022-1258
A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execut... Read more
Affected Products : agent- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1257
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database... Read more
Affected Products : agent- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1256
A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory w... Read more
Affected Products : agent- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1255
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues... Read more
Affected Products : import_and_export_users_and_customers- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1254
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicio... Read more
Affected Products : web_gateway- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1253
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.... Read more
Affected Products : libde265- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-1252
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an a... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1251
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.... Read more
Affected Products : ask_me- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1250
The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : lifterlms- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2022-1249
A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function fails to handle the NULL pwdata invocation from daemon.c, which leads to an explicit NULL dereference and crash on all attempts to daem... Read more
Affected Products : pesign- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1248
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web a... Read more
Affected Products : sap_information_system- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2022-1247
An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls ... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1245
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could all... Read more
- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024