Latest CVE Feed
-
6.1
MEDIUMCVE-2022-0385
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting... Read more
Affected Products : crazy_bone- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0384
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0383
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks... Read more
Affected Products : wp_review_slider- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0382
An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limi... Read more
Affected Products : linux_kernel- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0381
The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts... Read more
Affected Products : embed_swagger- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0380
The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use of $_SERVER['PHP_SELF'] found in the ~/options-fotobook.php file which allows attackers to inject arbitrary web scripts onto the page, i... Read more
Affected Products : fotobook- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0379
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0378
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0377
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to th... Read more
Affected Products : learnpress- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0376
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scriptin... Read more
Affected Products : user_meta_user_profile_builder_and_user_management- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0375
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0374
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0373
Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address... Read more
Affected Products : gitlab- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-0372
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.... Read more
Affected Products : crater- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0371
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0370
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0367
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0366
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.... Read more
Affected Products : capsule8- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-0365
The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024