Latest CVE Feed
-
5.3
MEDIUMCVE-2022-1328
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line... Read more
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1327
The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : image_gallery- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1326
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : form_-_contact_form- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1325
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from di... Read more
Affected Products : cimg- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1324
The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : event_timeline- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1323
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST reque... Read more
- Published: Aug. 08, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1322
The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : coming_soon- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1321
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when... Read more
Affected Products : google_authenticator- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-1320
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1319
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by C... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2022-1318
Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attack... Read more
- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1316
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation ... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1314
Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1313
Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-1312
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1311
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1310
Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-1309
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1308
Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1307
Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024