Latest CVE Feed
-
6.3
MEDIUMCVE-2022-0937
Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.... Read more
Affected Products : showdoc- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-0936
Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.... Read more
Affected Products : autolab- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0935
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.... Read more
Affected Products : live_helper_chat- Published: Apr. 07, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0932
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.... Read more
Affected Products : saleor- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2022-0930
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.... Read more
- Published: Mar. 12, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0929
XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.... Read more
- Published: Mar. 12, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0928
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0926
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.... Read more
- Published: Mar. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0924
Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0923
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute syst... Read more
Affected Products : diaenergie- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0922
The software does not perform any authentication for critical system functionality.... Read more
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0921
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0920
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data... Read more
Affected Products : salon_booking_system- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0919
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such... Read more
Affected Products : salon_booking_system- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0916
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.... Read more
Affected Products : options- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2022-0915
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.... Read more
Affected Products : sync- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0914
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker ... Read more
Affected Products : export_all_urls- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0913
Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0912
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0911
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.... Read more
Affected Products : pimcore- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024