Latest CVE Feed
-
6.6
MEDIUMCVE-2022-1283
NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).... Read more
Affected Products : radare2- Published: Apr. 08, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1282
The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.... Read more
Affected Products : photo_gallery- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1281
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.... Read more
Affected Products : photo_gallery- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-1280
A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.... Read more
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1279
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-client versions pr... Read more
Affected Products : ebics_java- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1278
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.... Read more
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1277
Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.... Read more
Affected Products : solar_log- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1276
Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.... Read more
Affected Products : mruby- Published: Apr. 10, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1275
The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite)... Read more
Affected Products : bannerman- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1274
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.... Read more
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-1273
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE... Read more
Affected Products : import_wp- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1269
The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : fastflow- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1268
The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting... Read more
Affected Products : donate_extra- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1267
The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : bmi_bmr_calculator- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1266
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : post_grid\,_slider_\&_carousel_ultimate- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1265
The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : bulletproof_security- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1264
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.... Read more
Affected Products : ignition- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1263
A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1262
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.... Read more
Affected Products : dir-867_firmware dir-878_firmware dir-3040_firmware dir-3060_firmware dir-882_firmware dir-1960_firmware dir-1360_firmware dir-1760_firmware dir-2640_firmware dir-2660_firmware +10 more products- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2022-1261
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-l... Read more
Affected Products : matrikon_opc_server- Published: May. 26, 2022
- Modified: Nov. 21, 2024