Latest CVE Feed
-
6.5
MEDIUMCVE-2022-0830
The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete ... Read more
Affected Products : formbuilder- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0829
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.... Read more
Affected Products : webmin- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0827
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users... Read more
Affected Products : bestbooks- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0826
The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users... Read more
Affected Products : wp-video-gallery-free- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0825
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone ... Read more
Affected Products : amelia- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2022-0824
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.... Read more
Affected Products : webmin- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2022-0823
An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.... Read more
Affected Products : gs1200-5_firmware gs1200-5hp_firmware gs1200-8_firmware gs1200-8hp_firmware gs1200-5 gs1200-5hp gs1200-8 gs1200-8hp- Published: Jun. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0822
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.... Read more
Affected Products : orchardcore- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0821
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.... Read more
Affected Products : orchardcore- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0820
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.... Read more
Affected Products : orchardcore- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0819
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.... Read more
Affected Products : dolibarr_erp\/crm- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0818
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloa... Read more
Affected Products : woocommerce_affiliate- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0817
The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users... Read more
- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0815
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected b... Read more
Affected Products : webadvisor- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0814
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Inje... Read more
Affected Products : ubigeo_de_peru_para_woocommerce- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0813
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.... Read more
Affected Products : phpmyadmin- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0812
An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information.... Read more
Affected Products : linux_kernel- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2022-0811
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluste... Read more
Affected Products : cri-o- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0809
Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0808
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024