Latest CVE Feed
-
7.2
HIGHCVE-2022-0267
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-0266
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.... Read more
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0265
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.... Read more
Affected Products : hazelcast- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0264
A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak in... Read more
Affected Products : linux_kernel- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0263
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-0262
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0260
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0258
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0257
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0256
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0255
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue... Read more
Affected Products : database_backup- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0254
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection... Read more
Affected Products : zero-spam- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0253
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0252
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : givewp- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0251
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.... Read more
Affected Products : pimcore- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0250
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : redirection_for_contact_form_7- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2022-0249
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0248
The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting a... Read more
Affected Products : contact_form_submissions- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0247
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36... Read more
Affected Products : fuchsia- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024