Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2022-0689

    Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.... Read more

    Affected Products : microweber cockpit
    • Published: Feb. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2022-0688

    Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.... Read more

    Affected Products : microweber cockpit
    • Published: Feb. 20, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0687

    The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom ... Read more

    Affected Products : amelia
    • Published: Mar. 21, 2022
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-0686

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.... Read more

    Affected Products : url-parse
    • Published: Feb. 20, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-0685

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.... Read more

    Affected Products : fedora debian_linux vim macos
    • Published: Feb. 20, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-0684

    The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more

    Affected Products : wp_home_page_menu
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0683

    The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows attackers to inject arbitrar... Read more

    Affected Products : essential_addons_for_elementor
    • Published: Feb. 24, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0681

    The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack... Read more

    Affected Products : simple_membership
    • Published: Mar. 21, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0680

    The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escaping, leading to a Stored Cross-Site ... Read more

    Affected Products : plezi
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0679

    The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticate... Read more

    Affected Products : narnoo_distributor
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0678

    Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.... Read more

    Affected Products : microweber cockpit
    • Published: Feb. 19, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-0677

    Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affect... Read more

    • Published: Apr. 07, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-0676

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.... Read more

    Affected Products : fedora radare2
    • Published: Feb. 22, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0675

    In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe ... Read more

    Affected Products : firewall
    • Published: Mar. 02, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-0674

    The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more

    Affected Products : kunze_law
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0673

    A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.... Read more

    Affected Products : lemminx
    • Published: Feb. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-0672

    A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.... Read more

    Affected Products : lemminx
    • Published: Feb. 18, 2022
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-0671

    A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.... Read more

    Affected Products : vscode-xml
    • Published: Feb. 18, 2022
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-0670

    A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to c... Read more

    Affected Products : fedora ceph_storage ceph ceph
    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0669

    A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending su... Read more

    • Published: Aug. 29, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294358 Results