Latest CVE Feed
-
4.8
MEDIUMCVE-2022-23179
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilte... Read more
Affected Products : contact_form_\&_lead_form_elementor_builder- EPSS Score: %0.15
- Published: Jan. 16, 2024
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2013-4253
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.... Read more
Affected Products : openshift- EPSS Score: %0.06
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2024-0881
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX act... Read more
Affected Products : post_grid- Published: Apr. 11, 2024
- Modified: May. 09, 2025
-
3.8
LOWCVE-2024-3628
The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : easyevent- Published: May. 07, 2024
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43023
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43021
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43020
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43019
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.... Read more
Affected Products : opencats- EPSS Score: %7.97
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-43018
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.... Read more
Affected Products : opencats- EPSS Score: %9.94
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-43017
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.... Read more
Affected Products : opencats- EPSS Score: %9.94
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-43016
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.... Read more
Affected Products : opencats- EPSS Score: %9.94
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-43015
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.... Read more
Affected Products : opencats- EPSS Score: %5.64
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-40885
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.... Read more
Affected Products : bento4- EPSS Score: %0.03
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-40884
Bento4 1.6.0 has memory leaks via the mp4fragment.... Read more
Affected Products : bento4- EPSS Score: %0.07
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-3327
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.... Read more
Affected Products : rdiffweb- EPSS Score: %0.11
- Published: Oct. 20, 2022
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2022-38901
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded ... Read more
- EPSS Score: %0.28
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.8
MEDIUMCVE-2022-35860
Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions.... Read more
- EPSS Score: %0.04
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2022-33077
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.... Read more
Affected Products : nopcommerce- EPSS Score: %0.16
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
4.3
MEDIUMCVE-2022-31684
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where... Read more
Affected Products : reactor_netty- EPSS Score: %0.24
- Published: Oct. 19, 2022
- Modified: May. 09, 2025