Latest CVE Feed
-
3.3
LOWCVE-2022-0987
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.... Read more
- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0986
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.... Read more
Affected Products : control_panel- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0985
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.... Read more
Affected Products : moodle- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0984
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.... Read more
- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0983
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.... Read more
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0982
The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client,... Read more
Affected Products : accel-ppp- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0981
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges th... Read more
Affected Products : quarkus- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0980
Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.... Read more
- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0979
Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0978
Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0977
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0976
Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0975
Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0974
Use after free in Splitscreen in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0973
Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0972
Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0971
Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0970
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.... Read more
Affected Products : grav- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0969
The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks... Read more
Affected Products : image_optimization_\&_lazy_load_by_optimole- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0968
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber... Read more
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024