Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2022-0210

    The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrar... Read more

    Affected Products : random_banner
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0208

    The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting... Read more

    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 4.7

    MEDIUM
    CVE-2022-0207

    A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.... Read more

    • Published: Aug. 26, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0206

    The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues... Read more

    Affected Products : newstatpress
    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0205

    The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue... Read more

    Affected Products : yop-poll yop_poll
    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0204

    A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.... Read more

    Affected Products : fedora debian_linux bluez
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-0203

    Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.... Read more

    Affected Products : crater
    • Published: Jan. 26, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0201

    The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue... Read more

    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0200

    Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a... Read more

    Affected Products : portfolio_post
    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2022-0199

    The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack... Read more

    Affected Products : coming_soon_and_maintenance_mode
    • Published: Feb. 21, 2022
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2022-0198

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference... Read more

    Affected Products : corenlp
    • Published: Jan. 13, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0197

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)... Read more

    Affected Products : fedora phoronix_test_suite
    • Published: Jan. 13, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0196

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)... Read more

    Affected Products : fedora phoronix_test_suite
    • Published: Jan. 13, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0194

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from th... Read more

    Affected Products : debian_linux netatalk
    • Published: Mar. 28, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0193

    The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting... Read more

    Affected Products : complianz
    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-0192

    A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.... Read more

    Affected Products : pcmanager
    • Published: Apr. 22, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-0191

    The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans... Read more

    Affected Products : ad_invalid_click_protector
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0190

    The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.... Read more

    Affected Products : ad_invalid_click_protector
    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0189

    The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting... Read more

    Affected Products : wp_rss_aggregator
    • Published: Feb. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2022-0188

    The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.... Read more

    Affected Products : cmp
    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294261 Results