Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-0949

    The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX ... Read more

    Affected Products : block_and_stop_bad_bots stopbadbots
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0948

    The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection... Read more

    Affected Products : order_listener_for_woocommerce
    • Published: May. 09, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0947

    A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.... Read more

    • Published: May. 10, 2022
    • Modified: Nov. 21, 2024
  • 9.0

    CRITICAL
    CVE-2022-0946

    Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 9.0

    CRITICAL
    CVE-2022-0945

    Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-0944

    Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.... Read more

    Affected Products : sqlpad
    • Published: Mar. 15, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-0943

    Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.... Read more

    Affected Products : fedora debian_linux vim macos
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2022-0942

    Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 15, 2022
    • Modified: Nov. 21, 2024
  • 7.3

    HIGH
    CVE-2022-0941

    Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2022-0940

    Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2022-0939

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.... Read more

    Affected Products : calibre-web calibre-web
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2022-0938

    Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2022-0937

    Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.... Read more

    Affected Products : showdoc
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2022-0936

    Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.... Read more

    Affected Products : autolab
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0935

    Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.... Read more

    Affected Products : live_helper_chat
    • Published: Apr. 07, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0932

    Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.... Read more

    Affected Products : saleor
    • Published: Mar. 11, 2022
    • Modified: Nov. 21, 2024
  • 8.0

    HIGH
    CVE-2022-0930

    File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.... Read more

    Affected Products : microweber cockpit
    • Published: Mar. 12, 2022
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2022-0929

    XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.... Read more

    Affected Products : microweber cockpit
    • Published: Mar. 12, 2022
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2022-0928

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.... Read more

    Affected Products : microweber cockpit
    • Published: Mar. 11, 2022
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2022-0926

    File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.... Read more

    Affected Products : microweber cockpit
    • Published: Mar. 12, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294528 Results