Latest CVE Feed
-
5.5
MEDIUMCVE-2022-42329
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a dea... Read more
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
6.2
MEDIUMCVE-2022-42328
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a dea... Read more
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
4.8
MEDIUMCVE-2022-41994
Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.... Read more
Affected Products : basercms- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-3907
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.... Read more
Affected Products : clerk.io- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-3858
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable b... Read more
Affected Products : chaty- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-3846
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.... Read more
Affected Products : workreap- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
4.8
MEDIUMCVE-2022-3838
The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa... Read more
Affected Products : wpupper_share_buttons- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39099
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39098
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39097
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39096
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39095
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39094
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39093
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39092
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39091
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39090
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-25630
An authenticated user can embed malicious content with XSS into the admin group policy page.... Read more
Affected Products : messaging_gateway- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-25629
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).... Read more
Affected Products : messaging_gateway- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-1540
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.... Read more
Affected Products : postmagthemes_demo_import- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025