Latest CVE Feed
-
6.5
MEDIUMCVE-2022-0374
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0373
Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address... Read more
Affected Products : gitlab- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2022-0372
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.... Read more
Affected Products : crater- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0371
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0370
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.... Read more
- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0367
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0366
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.... Read more
Affected Products : capsule8- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-0365
The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0364
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : modern_events_calendar_lite- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0363
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, mana... Read more
Affected Products : mycred- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0362
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.... Read more
Affected Products : showdoc- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0360
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cr... Read more
Affected Products : import_all_pages\,_post_types\,_products\,_orders\,_and_users_as_xml_\&_csv- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0358
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a s... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0357
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdef... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0355
Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1. ... Read more
Affected Products : simple-get- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0354
A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that ... Read more
Affected Products : system_update- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2022-0353
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. ... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024