Latest CVE Feed
-
6.1
MEDIUMCVE-2022-0257
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0256
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0255
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue... Read more
Affected Products : database_backup- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0254
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection... Read more
Affected Products : zero-spam- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0253
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0252
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : givewp- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0251
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.... Read more
Affected Products : pimcore- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0250
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : redirection_for_contact_form_7- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0249
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0248
The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting a... Read more
Affected Products : contact_form_submissions- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0247
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36... Read more
Affected Products : fuchsia- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2022-0246
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files ... Read more
Affected Products : iq_block_country- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-0245
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2022-0244
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.... Read more
Affected Products : gitlab- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2022-0243
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.... Read more
Affected Products : orchardcore- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0242
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.... Read more
Affected Products : crater- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0240
mruby is vulnerable to NULL Pointer Dereference... Read more
Affected Products : mruby- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0239
corenlp is vulnerable to Improper Restriction of XML External Entity Reference... Read more
Affected Products : corenlp- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.5
MEDIUM- Published: Jan. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0237
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in... Read more
Affected Products : insight_agent- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024