Latest CVE Feed
-
6.5
MEDIUMCVE-2022-0708
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.... Read more
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0705
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.... Read more
Affected Products : pimcore- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0704
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.... Read more
Affected Products : pimcore- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0703
The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : gd-mylist- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0702
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : petfinder-listings- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0701
The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : seo-301-meta- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0700
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : simple_tracking- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0697
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.... Read more
Affected Products : archivy- Published: Mar. 06, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUM- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0695
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0694
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users... Read more
Affected Products : advanced_booking_calendar- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0693
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to a... Read more
Affected Products : master_elements- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0692
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.... Read more
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0691
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.... Read more
Affected Products : url-parse- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0690
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0689
Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-0688
Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Feb. 20, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0687
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom ... Read more
Affected Products : amelia- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0686
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.... Read more
Affected Products : url-parse- Published: Feb. 20, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2022-0685
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.... Read more
- Published: Feb. 20, 2022
- Modified: Nov. 21, 2024