Latest CVE Feed
-
4.3
MEDIUMCVE-2022-1251
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.... Read more
Affected Products : ask_me- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1250
The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : lifterlms- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2022-1249
A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function fails to handle the NULL pwdata invocation from daemon.c, which leads to an explicit NULL dereference and crash on all attempts to daem... Read more
Affected Products : pesign- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1248
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web a... Read more
Affected Products : sap_information_system- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2022-1247
An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls ... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1245
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could all... Read more
- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-1244
heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.... Read more
Affected Products : radare2- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-1243
CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-1241
The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues... Read more
- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1240
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very li... Read more
Affected Products : radare2- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1239
The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks... Read more
Affected Products : hubspot- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1238
Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/de... Read more
Affected Products : radare2- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-1237
Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/12... Read more
Affected Products : radare2- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1236
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.... Read more
Affected Products : growi- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2022-1235
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1234
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise o... Read more
Affected Products : live_helper_chat- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-1233
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.... Read more
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-1232
Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-1231
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code... Read more
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2022-1230
This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit... Read more
- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024