Latest CVE Feed
-
5.3
MEDIUMCVE-2022-3818
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the G... Read more
Affected Products : gitlab- EPSS Score: %0.07
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
8.0
HIGHCVE-2022-3558
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.... Read more
Affected Products : import_and_export_users_and_customers- EPSS Score: %0.35
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2022-3537
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP... Read more
Affected Products : role_based_pricing_for_woocommerce- EPSS Score: %0.17
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2022-3536
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserializati... Read more
Affected Products : role_based_pricing_for_woocommerce- EPSS Score: %0.13
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2022-3494
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a ... Read more
Affected Products : complianz- EPSS Score: %0.41
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-3489
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request... Read more
Affected Products : wp_hide- EPSS Score: %0.11
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2022-3486
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.... Read more
Affected Products : gitlab- EPSS Score: %0.29
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-3481
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : woocommerce_dropshipping- EPSS Score: %1.09
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2022-3280
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.... Read more
Affected Products : gitlab- EPSS Score: %0.12
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.3
HIGHCVE-2022-3265
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a ... Read more
Affected Products : gitlab- EPSS Score: %52.85
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
6.7
MEDIUMCVE-2022-32611
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340373; Issue ID: ALP... Read more
- EPSS Score: %0.03
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.4
MEDIUMCVE-2022-32610
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203476; Issue ID: ALPS07203476.... Read more
- EPSS Score: %0.03
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.7
MEDIUMCVE-2022-21778
In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issue I... Read more
- EPSS Score: %0.01
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
3.3
LOWCVE-2022-20446
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-20445
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2025-27188
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security m... Read more
- Published: Apr. 08, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-36740
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.... Read more
Affected Products : oneflow- Published: Jun. 06, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-37384
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-37385
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-4620
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025