Export limit exceeded: 373410 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 373410 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373410 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-0214 | 1 Custom Popup Builder Project | 1 Custom Popup Builder | 2024-11-21 | 7.5 High |
| The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog | ||||
| CVE-2022-0213 | 2 Debian, Vim | 2 Debian Linux, Vim | 2024-11-21 | 6.6 Medium |
| vim is vulnerable to Heap-based Buffer Overflow | ||||
| CVE-2022-0212 | 1 10web | 1 Spidercalendar | 2024-11-21 | 6.1 Medium |
| The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue. | ||||
| CVE-2022-0211 | 1 Getshieldsecurity | 1 Shield Security | 2024-11-21 | 4.8 Medium |
| The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | ||||
| CVE-2022-0208 | 1 Mappresspro | 1 Mappress | 2024-11-21 | 6.1 Medium |
| The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting | ||||
| CVE-2022-0207 | 2 Ovirt, Redhat | 6 Vdsm, Enterprise Linux, Rhev Hypervisor and 3 more | 2024-11-21 | 4.7 Medium |
| A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text. | ||||
| CVE-2022-0206 | 1 Newstatpress Project | 1 Newstatpress | 2024-11-21 | 6.1 Medium |
| The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | ||||
| CVE-2022-0205 | 1 Yop-poll | 1 Yop-poll | 2024-11-21 | 5.4 Medium |
| The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue | ||||
| CVE-2022-0203 | 1 Craterapp | 1 Crater | 2024-11-21 | 5.3 Medium |
| Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. | ||||
| CVE-2022-0201 | 2 Permalink Manager Lite Project, Permalink Manager Project | 2 Permalink Manager Lite, Permalink Manager | 2024-11-21 | 6.1 Medium |
| The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue | ||||
| CVE-2022-0200 | 1 Themify | 1 Portfolio Post | 2024-11-21 | 5.4 Medium |
| Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting | ||||
| CVE-2022-0199 | 1 Wpdevart | 1 Coming Soon And Maintenance Mode | 2024-11-21 | 4.3 Medium |
| The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack | ||||
| CVE-2022-0198 | 1 Stanford | 1 Corenlp | 2024-11-21 | 7.1 High |
| corenlp is vulnerable to Improper Restriction of XML External Entity Reference | ||||
| CVE-2022-0197 | 2 Fedoraproject, Phoronix-media | 2 Fedora, Phoronix Test Suite | 2024-11-21 | 8.8 High |
| phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||||
| CVE-2022-0196 | 2 Fedoraproject, Phoronix-media | 2 Fedora, Phoronix Test Suite | 2024-11-21 | 8.8 High |
| phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||||
| CVE-2022-0193 | 1 Really-simple-plugins | 1 Complianz | 2024-11-21 | 6.1 Medium |
| The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | ||||
| CVE-2022-0192 | 1 Lenovo | 1 Pcmanager | 2024-11-21 | 7.3 High |
| A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation. | ||||
| CVE-2022-0191 | 1 Acnam | 1 Ad Invalid Click Protector | 2024-11-21 | 6.5 Medium |
| The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans | ||||
| CVE-2022-0190 | 1 Acnam | 1 Ad Invalid Click Protector | 2024-11-21 | 8.8 High |
| The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action. | ||||
| CVE-2022-0189 | 1 Wprssaggregator | 1 Wp Rss Aggregator | 2024-11-21 | 6.1 Medium |
| The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting | ||||