Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-0265

    Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.... Read more

    Affected Products : hazelcast
    • Published: Mar. 03, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-0264

    A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak in... Read more

    Affected Products : linux_kernel
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-0263

    Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.... Read more

    Affected Products : pimcore
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-0262

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.... Read more

    Affected Products : pimcore
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-0261

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.... Read more

    Affected Products : debian_linux vim macos mac_os_x
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0260

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.... Read more

    Affected Products : pimcore
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0258

    pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command... Read more

    Affected Products : pimcore
    • Published: Jan. 17, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0257

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    Affected Products : pimcore
    • Published: Jan. 17, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0256

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    Affected Products : pimcore
    • Published: Jan. 17, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-0255

    The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue... Read more

    Affected Products : database_backup
    • Published: Feb. 21, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0254

    The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection... Read more

    Affected Products : zero-spam
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2022-0253

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Jan. 17, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0252

    The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting... Read more

    Affected Products : givewp
    • Published: Feb. 21, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2022-0251

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.... Read more

    Affected Products : pimcore
    • Published: Jan. 26, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0250

    The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting... Read more

    Affected Products : redirection_for_contact_form_7
    • Published: Jul. 04, 2022
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2022-0249

    A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.... Read more

    Affected Products : gitlab
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0248

    The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting a... Read more

    Affected Products : contact_form_submissions
    • Published: Mar. 14, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-0247

    An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36... Read more

    Affected Products : fuchsia
    • Published: Feb. 25, 2022
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2022-0246

    The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files ... Read more

    Affected Products : iq_block_country
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2022-0245

    Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294273 Results