Export limit exceeded: 370169 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (370169 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0876 1 Wpdevart 1 Social Comments 2024-11-21 4.8 Medium
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-0875 1 Miniorange 1 Google Authenticator 2024-11-21 4.3 Medium
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
CVE-2022-0874 1 Wp-experts 1 Wp Social Buttons 2024-11-21 4.8 Medium
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-0873 1 Codeasily 1 Gmedia Gallery 2024-11-21 4.8 Medium
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed
CVE-2022-0871 1 Gogs 1 Gogs 2024-11-21 9.1 Critical
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-0870 1 Gogs 1 Gogs 2024-11-21 5.3 Medium
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-0869 1 Spirit-project 1 Spirit 2024-11-21 6.1 Medium
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
CVE-2022-0868 1 Uri.js Project 1 Uri.js 2024-11-21 6.1 Medium
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
CVE-2022-0867 1 Reputeinfosystems 1 Pricing Table 2024-11-21 9.8 Critical
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
CVE-2022-0865 5 Debian, Fedoraproject, Libtiff and 2 more 5 Debian Linux, Fedora, Libtiff and 2 more 2024-11-21 5.5 Medium
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
CVE-2022-0864 1 Updraftplus 1 Updraftplus 2024-11-21 6.1 Medium
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2022-0863 1 Wp Svg Icons Project 1 Wp Svg Icons 2024-11-21 7.2 High
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
CVE-2022-0862 1 Mcafee 1 Epolicy Orchestrator 2024-11-21 3.1 Low
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This functionality was removed from the User Interface in ePO 10 and the API has now been disabled. Other protection is in place to reduce the likelihood of this being successful through sending a link to a logged in user.
CVE-2022-0861 1 Mcafee 1 Epolicy Orchestrator 2024-11-21 3.5 Low
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.
CVE-2022-0860 2 Cobbler Project, Fedoraproject 2 Cobbler, Fedora 2024-11-21 9.1 Critical
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
CVE-2022-0859 1 Mcafee 1 Epolicy Orchestrator 2024-11-21 6.5 Medium
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server (restricted to administrators) and to know the SQL server password.
CVE-2022-0857 1 Mcafee 1 Epolicy Orchestrator 2024-11-21 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.
CVE-2022-0856 2 Fedoraproject, Libcaca Project 2 Fedora, Libcaca 2024-11-21 6.5 Medium
libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service
CVE-2022-0855 1 Microweber 1 Whmcs 2024-11-21 6.1 Medium
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
CVE-2022-0854 3 Debian, Linux, Redhat 5 Debian Linux, Linux Kernel, Enterprise Linux and 2 more 2024-11-21 5.5 Medium
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.