Latest CVE Feed
-
7.1
HIGHCVE-2022-0198
corenlp is vulnerable to Improper Restriction of XML External Entity Reference... Read more
Affected Products : corenlp- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0194
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from th... Read more
- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0193
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : complianz- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0192
A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.... Read more
Affected Products : pcmanager- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0191
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans... Read more
Affected Products : ad_invalid_click_protector- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0190
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.... Read more
Affected Products : ad_invalid_click_protector- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0189
The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : wp_rss_aggregator- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-0188
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.... Read more
Affected Products : cmp- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0186
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users ... Read more
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0184
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with ... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2022-0183
Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions allows an attacker who can physically access the device to obtain the stored passwords.... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0182
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-0181
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0180
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-0179
snipe-it is vulnerable to Missing Authorization... Read more
Affected Products : snipe-it- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2022-0178
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8. ... Read more
Affected Products : snipe-it- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0175
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitiali... Read more
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0174
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024