Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.1

    HIGH
    CVE-2022-0436

    Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.... Read more

    Affected Products : grunt
    • Published: Apr. 12, 2022
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2022-0435

    A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the sy... Read more

    • Published: Mar. 25, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0434

    The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attacker... Read more

    Affected Products : page_view_count
    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-0433

    A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prio... Read more

    Affected Products : linux_kernel fedora
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2022-0432

    Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.... Read more

    Affected Products : mastodon
    • Published: Feb. 02, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0431

    The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting... Read more

    Affected Products : insights_from_google_pagespeed
    • Published: Apr. 04, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2022-0430

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.... Read more

    Affected Products : httpie
    • Published: Mar. 15, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0429

    The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vuln... Read more

    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0428

    The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting... Read more

    Affected Products : content_egg
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2022-0427

    Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover... Read more

    Affected Products : gitlab
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0426

    The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflect... Read more

    Affected Products : product_feed_pro_for_woocommerce
    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2022-0425

    A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.... Read more

    Affected Products : gitlab
    • Published: Apr. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2022-0424

    The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users... Read more

    Affected Products : popup
    • Published: May. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-0423

    The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads i... Read more

    Affected Products : 3d_flipbook
    • Published: Mar. 21, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-0422

    The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue... Read more

    Affected Products : white_label_cms
    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-0420

    The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks... Read more

    Affected Products : registrationmagic
    • Published: Mar. 07, 2022
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2022-0419

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.... Read more

    Affected Products : fedora radare2
    • Published: Feb. 01, 2022
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2022-0418

    The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed... Read more

    Affected Products : event_list
    • Published: May. 02, 2022
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2022-0417

    Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.... Read more

    Affected Products : fedora debian_linux vim
    • Published: Feb. 01, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2022-0415

    Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.... Read more

    Affected Products : gogs
    • Published: Mar. 21, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294522 Results