Search

Search Results (377116 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0640 1 Wpdevart 1 Pricing Table Builder 2024-11-21 6.1 Medium
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0638 1 Microweber 1 Microweber 2024-11-21 4.3 Medium
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0636 1 Lenovo 1 Thin Installer 2024-11-21 5 Medium
A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.
CVE-2022-0635 2 Isc, Netapp 17 Bind, H300e, H300e Firmware and 14 more 2024-11-21 7.5 High
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.
CVE-2022-0634 1 Caseproof 1 Thirstyaffiliates Affiliate Link Manager 2024-11-21 4.3 Medium
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.
CVE-2022-0633 1 Updraftplus 1 Updraftplus 2024-11-21 6.5 Medium
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.
CVE-2022-0632 1 Mruby 1 Mruby 2024-11-21 5.5 Medium
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
CVE-2022-0631 1 Mruby 1 Mruby 2024-11-21 9.8 Critical
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
CVE-2022-0630 1 Mruby 1 Mruby 2024-11-21 7.1 High
Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-0629 4 Apple, Debian, Fedoraproject and 1 more 4 Macos, Debian Linux, Fedora and 1 more 2024-11-21 7.8 High
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0628 1 Accesspressthemes 1 Ap Mega Menu 2024-11-21 6.1 Medium
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0627 1 Tms-outsource 1 Amelia 2024-11-21 6.1 Medium
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0626 1 Kuroit 1 Advanced Admin Search 2024-11-21 6.1 Medium
The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting them back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0625 1 Admin Menu Editor Project 1 Admin Menu Editor 2024-11-21 6.1 Medium
The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0624 1 Parse-path Project 1 Parse-path 2024-11-21 7.3 High
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
CVE-2022-0623 1 Mruby 1 Mruby 2024-11-21 9.1 Critical
Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-0622 1 Snipeitapp 1 Snipe-it 2024-11-21 5.3 Medium
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-0621 1 Dtabs Project 1 Dtabs 2024-11-21 6.1 Medium
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0620 1 Deleteoldorders Project 1 Delete Old Orders 2024-11-21 6.1 Medium
The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0619 1 Database Peek Project 1 Database Peek 2024-11-21 6.1 Medium
The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.