Latest CVE Feed
-
4.8
MEDIUMCVE-2022-1113
The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is d... Read more
Affected Products : flower_delivery- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1112
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSR... Read more
Affected Products : autolinks- Published: Apr. 18, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the projec... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1110
A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.... Read more
Affected Products : smart_standby_driver- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1109
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.... Read more
Affected Products : leyun- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-1108
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-1107
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution... Read more
Affected Products : thinkpad_p51s_firmware thinkpad_p52s_firmware thinkpad_t570_firmware thinkpad_t580_firmware thinkpad_x1_yoga_firmware thinkpad_x280_firmware thinkpad_11e thinkpad_p51s thinkpad_p52s thinkpad_t570 +50 more products- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-1106
use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Mar. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1105
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1104
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : popup_maker- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1103
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE... Read more
Affected Products : advanced_uploader- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1102
A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/c... Read more
Affected Products : event_management_system- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1101
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The att... Read more
Affected Products : event_management_system- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponenti... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1099
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1098
Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges... Read more
Affected Products : diaenergie- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1095
The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more
Affected Products : _no_external_links_project- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1093
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered ... Read more
Affected Products : wp_meta_seo- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1092
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog... Read more
Affected Products : mycred- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1091
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugi... Read more
Affected Products : safe_svg- Published: Apr. 18, 2022
- Modified: Nov. 21, 2024