Latest CVE Feed
-
8.8
HIGHCVE-2022-42139
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.... Read more
- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-3912
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example... Read more
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
6.1
MEDIUMCVE-2022-3908
The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : helloprint- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2022-3883
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and ... Read more
Affected Products : stopbadbots- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2022-3882
The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and a... Read more
Affected Products : wp-memory- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-3359
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain... Read more
Affected Products : shortcodes_and_extra_features_for_phlox_theme- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2022-3104
An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.... Read more
Affected Products : linux_kernel- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
6.1
MEDIUMCVE-2022-38628
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attacke... Read more
- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-38488
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.... Read more
Affected Products : logrocket-oauth2-example- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-37155
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.... Read more
Affected Products : spip- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-33239
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdra... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware +458 more products- Published: Nov. 15, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-33237
Transient DOS due to buffer over-read in WLAN firmware while processing PPE threshold. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapd... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware +466 more products- Published: Nov. 15, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-33236
Transient DOS due to buffer over-read in WLAN firmware while parsing cipher suite info attributes. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking... Read more
Affected Products : qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware sd_8_gen1_5g_firmware sd865_5g_firmware sd870_firmware wcd9380_firmware wcn6850_firmware wcn6851_firmware +146 more products- Published: Nov. 15, 2022
- Modified: Apr. 22, 2025
-
8.2
HIGHCVE-2022-33235
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdra... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware +482 more products- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-33234
Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +210 more products- Published: Nov. 15, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-31703
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.... Read more
Affected Products : vrealize_log_insight- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-31702
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.... Read more
Affected Products : vrealize_network_insight- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2022-31701
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.... Read more
- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
7.2
HIGHCVE-2022-31700
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.... Read more
- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
3.3
LOWCVE-2022-31699
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.... Read more
- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025