Search Results (361364 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0224 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 9.8 Critical
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVE-2022-0221 1 Schneider-electric 1 Scadapack Workbench 2024-11-21 5.5 Medium
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)
CVE-2022-0220 1 Welaunch 1 Wordpress Gdpr\&ccpa 2024-11-21 6.1 Medium
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)
CVE-2022-0219 1 Jadx Project 1 Jadx 2024-11-21 5.5 Medium
Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.
CVE-2022-0217 1 Prosody 1 Prosody 2024-11-21 7.5 High
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).
CVE-2022-0216 2 Fedoraproject, Qemu 2 Fedora, Qemu 2024-11-21 4.4 Medium
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.
CVE-2022-0214 1 Custom Popup Builder Project 1 Custom Popup Builder 2024-11-21 7.5 High
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
CVE-2022-0213 2 Debian, Vim 2 Debian Linux, Vim 2024-11-21 6.6 Medium
vim is vulnerable to Heap-based Buffer Overflow
CVE-2022-0212 1 10web 1 Spidercalendar 2024-11-21 6.1 Medium
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.
CVE-2022-0211 1 Getshieldsecurity 1 Shield Security 2024-11-21 4.8 Medium
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
CVE-2022-0208 1 Mappresspro 1 Mappress 2024-11-21 6.1 Medium
The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting
CVE-2022-0207 2 Ovirt, Redhat 6 Vdsm, Enterprise Linux, Rhev Hypervisor and 3 more 2024-11-21 4.7 Medium
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
CVE-2022-0206 1 Newstatpress Project 1 Newstatpress 2024-11-21 6.1 Medium
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CVE-2022-0205 1 Yop-poll 1 Yop-poll 2024-11-21 5.4 Medium
The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
CVE-2022-0203 1 Craterapp 1 Crater 2024-11-21 5.3 Medium
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
CVE-2022-0201 2 Permalink Manager Lite Project, Permalink Manager Project 2 Permalink Manager Lite, Permalink Manager 2024-11-21 6.1 Medium
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
CVE-2022-0200 1 Themify 1 Portfolio Post 2024-11-21 5.4 Medium
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting
CVE-2022-0199 1 Wpdevart 1 Coming Soon And Maintenance Mode 2024-11-21 4.3 Medium
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
CVE-2022-0198 1 Stanford 1 Corenlp 2024-11-21 7.1 High
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2022-0197 2 Fedoraproject, Phoronix-media 2 Fedora, Phoronix Test Suite 2024-11-21 8.8 High
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)