Latest CVE Feed
-
7.1
HIGHCVE-2022-0144
shelljs is vulnerable to Improper Privilege Management... Read more
Affected Products : shelljs- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0143
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Ser... Read more
Affected Products : ldap_connector- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0142
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : visual_form_builder- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0141
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks... Read more
Affected Products : visual_form_builder- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0140
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.... Read more
Affected Products : visual_form_builder- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0139
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.... Read more
Affected Products : radare2- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0138
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be crea... Read more
Affected Products : mimosa_management_platform c6x_firmware c5x_firmware c5c_firmware a5x_firmware c6x c5x c5c a5x- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0137
A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.... Read more
Affected Products : htmldoc- Published: Nov. 14, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0136
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0135
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or poss... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0134
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack... Read more
Affected Products : anycomment- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0133
peertube is vulnerable to Improper Access Control... Read more
Affected Products : peertube- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0132
peertube is vulnerable to Server-Side Request Forgery (SSRF)... Read more
Affected Products : peertube- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2022-0131
Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.... Read more
Affected Products : jimoty- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0130
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file t... Read more
Affected Products : tenable.sc- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2022-0129
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious D... Read more
Affected Products : techcheck- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0128
vim is vulnerable to Out-of-bounds Read... Read more
- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0125
An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had t... Read more
Affected Products : gitlab- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0124
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.... Read more
Affected Products : gitlab- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0123
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024