Search Results (361327 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0151 1 Gitlab 1 Gitlab 2024-11-21 6.5 Medium
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions.
CVE-2022-0150 1 Wp Accessibility Helper Project 1 Wp Accessibility Helper 2024-11-21 6.1 Medium
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue
CVE-2022-0149 1 Visser 1 Store Exporter For Woocommerce 2024-11-21 6.1 Medium
The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.
CVE-2022-0148 1 Premio 1 Mystickyelements 2024-11-21 5.4 Medium
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
CVE-2022-0147 1 Cookieinformation 1 Wp-gdpr-compliance 2024-11-21 6.1 Medium
The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
CVE-2022-0145 1 Fork-cms 1 Fork Cms 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.
CVE-2022-0144 2 Redhat, Shelljs Project 2 Acm, Shelljs 2024-11-21 7.1 High
shelljs is vulnerable to Improper Privilege Management
CVE-2022-0142 1 Vfbpro 1 Visual Form Builder 2024-11-21 9.8 Critical
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
CVE-2022-0141 1 Vfbpro 1 Visual Form Builder 2024-11-21 8.1 High
The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks
CVE-2022-0140 1 Vfbpro 1 Visual Form Builder 2024-11-21 5.3 Medium
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
CVE-2022-0139 1 Radare 1 Radare2 2024-11-21 9.8 Critical
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2022-0136 1 Gitlab 1 Gitlab 2024-11-21 5.4 Medium
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
CVE-2022-0135 3 Debian, Redhat, Virglrenderer Project 3 Debian Linux, Enterprise Linux, Virglrenderer 2024-11-21 7.8 High
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
CVE-2022-0134 1 Bologer 1 Anycomment 2024-11-21 8.8 High
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack
CVE-2022-0133 1 Framasoft 1 Peertube 2024-11-21 7.5 High
peertube is vulnerable to Improper Access Control
CVE-2022-0132 1 Framasoft 1 Peertube 2024-11-21 7.5 High
peertube is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2022-0131 1 Jmty 1 Jimoty 2024-11-21 3.3 Low
Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
CVE-2022-0130 1 Tenable 1 Tenable.sc 2024-11-21 8.1 High
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server root of the Tenable.sc host prior to remote exploitation.
CVE-2022-0129 1 Mcafee 1 Techcheck 2024-11-21 7.4 High
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.
CVE-2022-0128 2 Apple, Vim 3 Mac Os X, Macos, Vim 2024-11-21 7.8 High
vim is vulnerable to Out-of-bounds Read