Latest CVE Feed
-
8.4
HIGH- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0442
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.... Read more
Affected Products : userswp- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0441
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin... Read more
Affected Products : masterstudy_lms- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0440
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED... Read more
Affected Products : catch_themes_demo_import- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0439
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subs... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0437
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.... Read more
Affected Products : karma- Published: Feb. 05, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0436
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.... Read more
Affected Products : grunt- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2022-0435
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the sy... Read more
Affected Products : linux_kernel enterprise_linux fedora enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus h300s_firmware h500s_firmware h700s_firmware h410s_firmware +27 more products- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0434
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attacker... Read more
Affected Products : page_view_count- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0433
A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prio... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2022-0432
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.... Read more
Affected Products : mastodon- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0431
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting... Read more
Affected Products : insights_from_google_pagespeed- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0430
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.... Read more
Affected Products : httpie- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0429
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vuln... Read more
Affected Products : wp_cerber_security\,_anti-spam_\&_malware_scan- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0428
The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : content_egg- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0427
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0426
The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflect... Read more
Affected Products : product_feed_pro_for_woocommerce- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-0425
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.... Read more
Affected Products : gitlab- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0424
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users... Read more
Affected Products : popup- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0423
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads i... Read more
Affected Products : 3d_flipbook- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024