Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-1244

    heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.... Read more

    Affected Products : radare2
    • Published: Apr. 05, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-1243

    CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.... Read more

    Affected Products : uri.js urijs
    • Published: Apr. 05, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-1241

    The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues... Read more

    Affected Products : ask_me ask_me
    • Published: Jun. 08, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1240

    Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very li... Read more

    Affected Products : radare2
    • Published: Apr. 06, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-1239

    The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks... Read more

    Affected Products : hubspot
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1238

    Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/de... Read more

    Affected Products : radare2
    • Published: Apr. 06, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1237

    Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/12... Read more

    Affected Products : radare2
    • Published: Apr. 06, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-1236

    Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.... Read more

    Affected Products : growi
    • Published: Apr. 05, 2022
    • Modified: Nov. 21, 2024
  • 8.2

    HIGH
    CVE-2022-1235

    Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Apr. 05, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-1234

    XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise o... Read more

    Affected Products : live_helper_chat
    • Published: Apr. 06, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-1233

    URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.... Read more

    Affected Products : uri.js urijs
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-1232

    Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more

    Affected Products : chrome edge_chromium
    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-1231

    XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code... Read more

    Affected Products : fedora plantuml
    • Published: Apr. 15, 2022
    • Modified: Nov. 21, 2024
  • 3.9

    LOW
    CVE-2022-1230

    This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit... Read more

    Affected Products : galaxy_s21_firmware galaxy_s21
    • Published: Mar. 28, 2023
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-1229

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a... Read more

    Affected Products : microstation_connect
    • Published: Mar. 28, 2023
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-1228

    The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" field, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more

    Affected Products : opeansea
    • Published: Apr. 25, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-1227

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command... Read more

    • Published: Apr. 29, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-1225

    Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.... Read more

    Affected Products : phpipam
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-1224

    Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.... Read more

    Affected Products : phpipam
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-1223

    Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. ... Read more

    Affected Products : phpipam
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294513 Results