Latest CVE Feed
-
7.5
HIGHCVE-2022-0624
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.... Read more
Affected Products : parse-path- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0623
Out-of-bounds Read in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0622
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.... Read more
Affected Products : snipe-it- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0621
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : dtabs- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0620
The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : delete_old_orders- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0619
The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : database_peek- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0618
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PROMISE frame wher... Read more
Affected Products : swiftnio_http\/2- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0617
A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0616
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack... Read more
Affected Products : amelia- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0615
Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-service condition on the system.... Read more
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2022-0614
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0613
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2022-0612
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0611
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11. ... Read more
Affected Products : snipe-it- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0610
Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0608
Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0607
Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0606
Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0605
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafte... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0604
Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024