Latest CVE Feed
-
8.8
HIGHCVE-2022-0456
Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0455
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0454
Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0453
Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0452
Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0451
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a re... Read more
Affected Products : dart_software_development_kit- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0450
The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the se... Read more
Affected Products : menu_image\,_icons_made_easy- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0449
The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in some pages such as the user dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : flexi- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0448
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.... Read more
Affected Products : cp_blocks- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2022-0447
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading t... Read more
Affected Products : post_grid- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0446
The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : simple_banner- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0445
The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack... Read more
Affected Products : wordpress_real_cookie_banner- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0444
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new bac... Read more
Affected Products : xcloner- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0442
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.... Read more
Affected Products : userswp- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0441
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin... Read more
Affected Products : masterstudy_lms- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0440
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED... Read more
Affected Products : catch_themes_demo_import- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0439
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subs... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0437
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.... Read more
Affected Products : karma- Published: Feb. 05, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0436
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.... Read more
Affected Products : grunt- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024