Latest CVE Feed
-
3.5
LOWCVE-2022-0279
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users... Read more
Affected Products : anycomment- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0278
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0277
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0274
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.... Read more
Affected Products : orchardcore- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Jan. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0272
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.... Read more
Affected Products : detekt- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0271
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : learnpress- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0270
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.... Read more
Affected Products : bored-agent- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2022-0269
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.... Read more
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-0268
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.... Read more
Affected Products : grav- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0267
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-0266
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.... Read more
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0265
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.... Read more
Affected Products : hazelcast- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0264
A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak in... Read more
Affected Products : linux_kernel- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0263
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-0262
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0260
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0258
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0257
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024