Latest CVE Feed
-
8.6
HIGHCVE-2022-0244
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.... Read more
Affected Products : gitlab- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2022-0243
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.... Read more
Affected Products : orchardcore- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0242
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.... Read more
Affected Products : crater- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0240
mruby is vulnerable to NULL Pointer Dereference... Read more
Affected Products : mruby- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0239
corenlp is vulnerable to Improper Restriction of XML External Entity Reference... Read more
Affected Products : corenlp- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.5
MEDIUM- Published: Jan. 16, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0237
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in... Read more
Affected Products : insight_agent- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0236
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-w... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0235
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor... Read more
- Published: Jan. 16, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0234
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the resp... Read more
Affected Products : woocs- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2022-0233
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-a... Read more
Affected Products : profilegrid- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0232
The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with admin... Read more
Affected Products : leadmagic- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0230
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admin... Read more
Affected Products : bwp-google-xml-sitemaps- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0229
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could ... Read more
Affected Products : google_authenticator- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0228
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection... Read more
Affected Products : popup_builder- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUM- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0225
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.... Read more
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0224
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command... Read more
Affected Products : dolibarr_erp\/crm- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0223
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthe... Read more
Affected Products : ecostruxure_power_commission- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024