Latest CVE Feed
-
7.8
HIGHCVE-2022-0646
A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system... Read more
Affected Products : linux_kernel h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s h700s +7 more products- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0645
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.... Read more
Affected Products : posthog- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0643
The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : bank_mellat- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0642
The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can tric... Read more
Affected Products : jivochat- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0641
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : popup_like_box- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0640
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : pricing_table_builder- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0639
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.... Read more
Affected Products : url-parse- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0638
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0636
A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.... Read more
Affected Products : thin_installer- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0635
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.... Read more
Affected Products : h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware bind h300s h410s h500s h700s +7 more products- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0634
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0633
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to ... Read more
Affected Products : updraftplus- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0632
NULL Pointer Dereference in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0631
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0630
Out-of-bounds Read in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0628
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : ap_mega_menu- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0627
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : amelia- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0626
The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting them back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : advanced_admin_search- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0625
The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : admin_menu_editor- Published: May. 09, 2022
- Modified: Nov. 21, 2024