Search Results (361510 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0705 1 Pimcore 1 Pimcore 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0704 1 Pimcore 1 Pimcore 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0703 1 Gd-mylist Project 1 Gd-mylist 2024-11-21 4.8 Medium
The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0702 1 Unboxinteractive 1 Petfinder-listings 2024-11-21 4.8 Medium
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0701 1 Seo-301-meta Project 1 Seo-301-meta 2024-11-21 4.8 Medium
The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0700 1 Chrsinteractive 1 Simple Tracking 2024-11-21 4.8 Medium
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0697 1 Archivy Project 1 Archivy 2024-11-21 6.1 Medium
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
CVE-2022-0696 4 Apple, Debian, Fedoraproject and 1 more 4 Macos, Debian Linux, Fedora and 1 more 2024-11-21 5.5 Medium
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
CVE-2022-0695 2 Fedoraproject, Radare 2 Fedora, Radare2 2024-11-21 5.5 Medium
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
CVE-2022-0694 1 Elbtide 1 Advanced Booking Calendar 2024-11-21 9.8 Critical
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CVE-2022-0693 1 Devbunch 1 Master Elements 2024-11-21 9.8 Critical
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection
CVE-2022-0692 1 Alltube Project 1 Alltube 2024-11-21 6.1 Medium
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
CVE-2022-0691 2 Redhat, Url-parse Project 2 Rhmt, Url-parse 2024-11-21 9.8 Critical
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
CVE-2022-0690 1 Microweber 1 Microweber 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0689 1 Microweber 1 Microweber 2024-11-21 5.3 Medium
Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0688 1 Microweber 1 Microweber 2024-11-21 4.9 Medium
Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0687 1 Tms-outsource 1 Amelia 2024-11-21 8.8 High
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.
CVE-2022-0686 2 Redhat, Url-parse Project 2 Rhmt, Url-parse 2024-11-21 9.1 Critical
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
CVE-2022-0685 4 Apple, Debian, Fedoraproject and 1 more 4 Macos, Debian Linux, Fedora and 1 more 2024-11-21 7.8 High
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
CVE-2022-0684 1 Wp Home Page Menu Project 1 Wp Home Page Menu 2024-11-21 4.8 Medium
The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed