Latest CVE Feed
-
7.8
HIGHCVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0545
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0544
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0542
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.... Read more
Affected Products : chatwoot- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0541
The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.... Read more
Affected Products : flo-launch- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0540
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.2... Read more
- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-0539
Cross-site Scripting (XSS) - Stored in Packagist ptrofimov/beanstalk_console prior to 1.7.14.... Read more
Affected Products : beanstalk_console- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0538
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.... Read more
Affected Products : jenkins- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0537
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to t... Read more
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2022-0536
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8. ... Read more
Affected Products : follow-redirects- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0535
The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : e2pdf- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0534
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0533
The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : ditty- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2022-0532
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kern... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0531
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting... Read more
Affected Products : migration\,_backup\,_staging- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0530
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code executi... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0529
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code executi... Read more
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0528
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1. ... Read more
Affected Products : uppy- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0527
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.... Read more
Affected Products : chatwoot- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2022-0526
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.... Read more
Affected Products : chatwoot- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024