Latest CVE Feed
-
5.5
MEDIUMCVE-2022-0286
A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.... Read more
- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-0285
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.... Read more
Affected Products : pimcore- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-0284
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file... Read more
Affected Products : imagemagick- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0283
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0282
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11. ... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0281
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0280
A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being del... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-0279
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users... Read more
Affected Products : anycomment- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0278
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0277
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2022-0274
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.... Read more
Affected Products : orchardcore- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Jan. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0272
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.... Read more
Affected Products : detekt- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0271
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : learnpress- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0270
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.... Read more
Affected Products : bored-agent- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2022-0269
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.... Read more
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-0268
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.... Read more
Affected Products : grav- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0267
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2022-0266
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.... Read more
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0265
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.... Read more
Affected Products : hazelcast- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024