Latest CVE Feed
-
6.1
MEDIUMCVE-2022-0234
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the resp... Read more
Affected Products : woocs- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2022-0233
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-a... Read more
Affected Products : profilegrid- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0232
The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with admin... Read more
Affected Products : leadmagic- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0230
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admin... Read more
Affected Products : bwp-google-xml-sitemaps- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0229
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could ... Read more
Affected Products : google_authenticator- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0228
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection... Read more
Affected Products : popup_builder- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUM- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0225
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.... Read more
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0224
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command... Read more
Affected Products : dolibarr_erp\/crm- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0223
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthe... Read more
Affected Products : ecostruxure_power_commission- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0222
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3... Read more
Affected Products : modicon_m340_bmxp341000_firmware modicon_m340_bmxp342010_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342030_firmware modicon_m340_bmxp342000_firmware modicon_m340_bmxp3420102_firmware modicon_m340_bmxp342020h_firmware modicon_m340_bmxp3420302_firmware modicon_m340_bmxp3420302h_firmware modicon_m340_bmxp342030h_firmware +18 more products- Published: Nov. 22, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0221
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data... Read more
Affected Products : scadapack_workbench- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0220
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properl... Read more
Affected Products : wordpress_gdpr\&ccpa- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0219
Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.... Read more
Affected Products : jadx- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2022-0218
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-tem... Read more
Affected Products : wordpress_email_template_designer- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0217
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE... Read more
Affected Products : prosody- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2022-0216
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileg... Read more
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0215
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/c... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0214
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog... Read more
Affected Products : custom_popup_builder- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024