Latest CVE Feed
-
9.1
CRITICALCVE-2022-0871
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.... Read more
Affected Products : gogs- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0870
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.... Read more
Affected Products : gogs- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0869
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.... Read more
Affected Products : spirit- Published: Mar. 06, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2022-0868
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.... Read more
- Published: Mar. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0867
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users... Read more
Affected Products : pricing_table- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0866
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsId... Read more
- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0865
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0864
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : updraftplus- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0863
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.... Read more
Affected Products : wp_svg_icons- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0862
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's pa... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0861
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some acc... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0860
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2022-0859
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server h... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2022-0858
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully c... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0857
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a c... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0856
libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2022-0855
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.... Read more
Affected Products : whmcs- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0854
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0853
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0852
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024