Search Results (357541 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0411 1 Asgaros 1 Asgaros Forum 2024-11-21 8.8 High
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection
CVE-2022-0409 1 Showdoc 1 Showdoc 2024-11-21 7.8 High
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
CVE-2022-0408 3 Debian, Fedoraproject, Vim 3 Debian Linux, Fedora, Vim 2024-11-21 7.8 High
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0407 1 Vim 1 Vim 2024-11-21 7.8 High
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0406 1 Janeczku 1 Calibre-web 2024-11-21 4.3 Medium
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
CVE-2022-0405 1 Janeczku 1 Calibre-web 2024-11-21 4.3 Medium
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
CVE-2022-0404 1 Material Design For Contact Form 7 Project 1 Material Design For Contact Form 7 2024-11-21 6.5 Medium
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.
CVE-2022-0403 1 Wpjos 1 Library File Manager 2024-11-21 8.1 High
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.
CVE-2022-0401 1 W-zip Project 1 W-zip 2024-11-21 9.8 Critical
Path Traversal in NPM w-zip prior to 1.0.12.
CVE-2022-0400 1 Linux 1 Linux Kernel 2024-11-21 7.5 High
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.
CVE-2022-0399 1 Berocket 1 Advanced Product Labels For Woocommerce 2024-11-21 6.1 Medium
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting
CVE-2022-0398 1 Caseproof 1 Thirstyaffiliates Affiliate Link Manager 2024-11-21 5.4 Medium
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website
CVE-2022-0397 1 Wpclever 1 Wpc Smart Wishlist For Woocommerce 2024-11-21 5.4 Medium
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting
CVE-2022-0396 5 Fedoraproject, Isc, Netapp and 2 more 20 Fedora, Bind, H300e and 17 more 2024-11-21 5.3 Medium
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection.
CVE-2022-0395 1 Livehelperchat 1 Live Helper Chat 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-0393 2 Fedoraproject, Vim 2 Fedora, Vim 2024-11-21 7.1 High
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-0390 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.
CVE-2022-0389 1 Codepeople 1 Wp Time Slots Booking Form 2024-11-21 4.8 Medium
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-0388 1 Humananatomyillustrations 1 Interactive Medical Drawing Of Human Body 2024-11-21 4.8 Medium
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-0387 1 Livehelperchat 1 Livehelperchat 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.