Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.4

    HIGH
    CVE-2022-0413

    Use After Free in GitHub repository vim/vim prior to 8.2.... Read more

    Affected Products : fedora debian_linux vim
    • Published: Jan. 30, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0412

    The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allow... Read more

    Affected Products : ti_woocommerce_wishlist
    • Published: Feb. 28, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0411

    The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection... Read more

    Affected Products : asgaros_forum
    • Published: Feb. 28, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0410

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection... Read more

    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-0409

    Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.... Read more

    Affected Products : showdoc
    • Published: Feb. 19, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-0408

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.... Read more

    Affected Products : fedora debian_linux vim
    • Published: Jan. 30, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-0407

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.... Read more

    Affected Products : vim
    • Published: Jan. 30, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2022-0406

    Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.... Read more

    Affected Products : calibre-web calibre-web
    • Published: Apr. 03, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2022-0405

    Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.... Read more

    Affected Products : calibre-web calibre-web
    • Published: Apr. 03, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0404

    The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in u... Read more

    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2022-0403

    The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX... Read more

    Affected Products : library_file_manager
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0401

    Path Traversal in NPM w-zip prior to 1.0.12.... Read more

    Affected Products : w-zip
    • Published: Feb. 01, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-0400

    An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.... Read more

    Affected Products : linux_kernel
    • Published: Aug. 29, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0399

    The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Sit... Read more

    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0398

    The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which ... Read more

    • Published: Apr. 25, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0397

    The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cr... Read more

    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2022-0396

    BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even aft... Read more

    • Published: Mar. 23, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0395

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0394

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-0393

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.... Read more

    Affected Products : fedora vim
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294289 Results