Latest CVE Feed
-
5.5
MEDIUMCVE-2022-0726
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.... Read more
Affected Products : peertube- Published: Feb. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0725
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0724
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.... Read more
- Published: Feb. 23, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2022-0723
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.... Read more
- Published: Feb. 26, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0722
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.... Read more
Affected Products : parse-url- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0721
Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.... Read more
- Published: Feb. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0720
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number ... Read more
Affected Products : amelia- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-0719
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.... Read more
- Published: Feb. 23, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2022-0718
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0717
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 23, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0715
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series I... Read more
Affected Products : smt_series_1015_ups_firmware smc_series_1018_ups_firmware smtl_series_1026_ups_firmware scl_series_1029_ups_firmware scl_series_1030_ups_firmware scl_series_1036_ups_firmware scl_series_1037_ups_firmware smx_series_1031_ups_firmware smt_series_18_ups_firmware smt_series_1040_ups_firmware +56 more products- Published: Mar. 09, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2022-0714
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.... Read more
- Published: Feb. 22, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0713
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.... Read more
- Published: Feb. 22, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0712
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.... Read more
- Published: Feb. 22, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0711
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition... Read more
Affected Products : enterprise_linux debian_linux openshift_container_platform software_collections haproxy- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0710
The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter.... Read more
Affected Products : header_footer_code_manager- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0709
The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data ... Read more
Affected Products : booking_package- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0708
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.... Read more
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0705
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.... Read more
Affected Products : pimcore- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0704
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.... Read more
Affected Products : pimcore- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024