Latest CVE Feed
-
7.1
HIGHCVE-2022-0630
Out-of-bounds Read in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0628
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : ap_mega_menu- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0627
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : amelia- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0626
The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting them back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : advanced_admin_search- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0625
The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : admin_menu_editor- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0624
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.... Read more
Affected Products : parse-path- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0623
Out-of-bounds Read in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0622
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.... Read more
Affected Products : snipe-it- Published: Feb. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0621
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : dtabs- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0620
The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : delete_old_orders- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0619
The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : database_peek- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0618
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PROMISE frame wher... Read more
Affected Products : swiftnio_http\/2- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0617
A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0616
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack... Read more
Affected Products : amelia- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0615
Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-service condition on the system.... Read more
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2022-0614
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0613
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2022-0612
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0611
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11. ... Read more
Affected Products : snipe-it- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024