Latest CVE Feed
-
6.1
MEDIUMCVE-2022-0422
The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : white_label_cms- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2022-0420
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks... Read more
Affected Products : registrationmagic- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2022-0419
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.... Read more
- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2022-0418
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed... Read more
Affected Products : event_list- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-0415
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.... Read more
Affected Products : gogs- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0414
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Jan. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0412
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allow... Read more
Affected Products : ti_woocommerce_wishlist- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0411
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection... Read more
Affected Products : asgaros_forum- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-0410
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0409
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.... Read more
Affected Products : showdoc- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
8.4
HIGH- Published: Jan. 30, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-0407
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.... Read more
Affected Products : vim- Published: Jan. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0406
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.... Read more
- Published: Apr. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0405
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.... Read more
- Published: Apr. 03, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-0404
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in u... Read more
Affected Products : material_design_for_contact_form_7- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-0403
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX... Read more
Affected Products : library_file_manager- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-0400
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.... Read more
Affected Products : linux_kernel- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024