Search Results (30286 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-1986 1 Gogs 1 Gogs 2024-11-21 9.8 Critical
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1953 1 Product Configurator For Woocommerce Project 1 Product Configurator For Woocommerce 2024-11-21 9.1 Critical
The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first
CVE-2022-1950 1 Kainelabs 1 Youzify 2024-11-21 9.8 Critical
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
CVE-2022-1905 1 E-dynamics 1 Events Made Easy 2024-11-21 9.8 Critical
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVE-2022-1899 1 Radare 1 Radare2 2024-11-21 9.1 Critical
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.
CVE-2022-1853 1 Google 1 Chrome 2024-11-21 9.6 Critical
Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2022-1813 1 Rengine Project 1 Rengine 2024-11-21 9.8 Critical
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
CVE-2022-1795 1 Gpac 1 Gpac 2024-11-21 9.8 Critical
Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.
CVE-2022-1775 1 Trudesk Project 1 Trudesk 2024-11-21 9.8 Critical
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-1731 1 Allgeier 1 Metasonic Doc Webclient 2024-11-21 9.8 Critical
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.
CVE-2022-1715 1 Facturascripts 1 Facturascripts 2024-11-21 9.8 Critical
Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.
CVE-2022-1692 1 Dwbooster 1 Cp Image Store With Slideshow 2024-11-21 9.8 Critical
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack
CVE-2022-1680 1 Gitlab 1 Gitlab 2024-11-21 9.9 Critical
An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.
CVE-2022-1664 2 Debian, Netapp 3 Debian Linux, Dpkg, Ontap Select Deploy Administration Utility 2024-11-21 9.8 Critical
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.
CVE-2022-1587 4 Fedoraproject, Netapp, Pcre and 1 more 17 Fedora, Active Iq Unified Manager, H300s and 14 more 2024-11-21 9.1 Critical
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
CVE-2022-1575 1 Diagrams 1 Drawio 2024-11-21 9.6 Critical
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
CVE-2022-1574 1 Html2wp Project 1 Html2wp 2024-11-21 9.8 Critical
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
CVE-2022-1556 1 Era404 1 Stafflist 2024-11-21 9.8 Critical
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection
CVE-2022-1531 1 Rtx Project 1 Rtx 2024-11-21 9.8 Critical
SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.
CVE-2022-1509 1 Hestiacp 1 Control Panel 2024-11-21 9.9 Critical
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.