Latest CVE Feed
-
5.5
MEDIUMCVE-2022-33180
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.... Read more
Affected Products : fabric_operating_system- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
8.8
HIGHCVE-2022-33179
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges.... Read more
Affected Products : fabric_operating_system- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
6.7
MEDIUMCVE-2024-20012
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ... Read more
- Published: Feb. 05, 2024
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-31468
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.... Read more
Affected Products : ox_app_suite- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-28170
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.... Read more
Affected Products : fabric_operating_system- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
8.8
HIGHCVE-2022-28169
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By e... Read more
Affected Products : fabric_operating_system- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2024-0239
The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.... Read more
Affected Products : contact_form_7_connector- Published: Jan. 16, 2024
- Modified: May. 09, 2025
-
4.8
MEDIUMCVE-2022-23179
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilte... Read more
Affected Products : contact_form_\&_lead_form_elementor_builder- Published: Jan. 16, 2024
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2013-4253
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.... Read more
Affected Products : openshift- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2024-0881
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX act... Read more
Affected Products : post_grid- Published: Apr. 11, 2024
- Modified: May. 09, 2025
-
3.8
LOWCVE-2024-3628
The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : easyevent- Published: May. 07, 2024
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-40885
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.... Read more
Affected Products : bento4- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-40884
Bento4 1.6.0 has memory leaks via the mp4fragment.... Read more
Affected Products : bento4- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-3327
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.... Read more
Affected Products : rdiffweb- Published: Oct. 20, 2022
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2022-38901
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded ... Read more
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.8
MEDIUMCVE-2022-35860
Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions.... Read more
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2022-33077
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.... Read more
Affected Products : nopcommerce- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
4.3
MEDIUMCVE-2022-31684
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where... Read more
Affected Products : reactor_netty- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-2805
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.... Read more
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2022-25736
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware +476 more products- Published: Oct. 19, 2022
- Modified: May. 09, 2025