Search Results (30283 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-1106 1 Mruby 1 Mruby 2024-11-21 9.1 Critical
use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-1057 1 Varktech 1 Pricing Deals For Woocommerce 2024-11-21 9.8 Critical
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
CVE-2022-1053 2 Fedoraproject, Keylime 2 Fedora, Keylime 2024-11-21 9.1 Critical
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1,
CVE-2022-1020 1 Codeastrology 1 Woo Product Table 2024-11-21 9.8 Critical
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument
CVE-2022-1014 1 Labarta 1 Wp Contacts Manager 2024-11-21 9.8 Critical
The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.
CVE-2022-1013 1 Ays-pro 1 Personal Dictionary 2024-11-21 9.8 Critical
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
CVE-2022-0990 1 Janeczku 1 Calibre-web 2024-11-21 9.1 Critical
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
CVE-2022-0982 1 Accel-ppp 1 Accel-ppp 2024-11-21 9.8 Critical
The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client, crafted client requests can remotely trigger this vulnerability.
CVE-2022-0977 1 Google 1 Chrome 2024-11-21 9.6 Critical
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-0973 1 Google 1 Chrome 2024-11-21 9.6 Critical
Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-0949 1 Stopbadbots 1 Block And Stop Bad Bots 2024-11-21 9.8 Critical
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection
CVE-2022-0948 1 Pluginbazaar 1 Order Listener For Woocommerce 2024-11-21 9.8 Critical
The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection
CVE-2022-0947 1 Abb 48 Arc600a2323na, Arc600a2323na Firmware, Arc600a2324na and 45 more 2024-11-21 9 Critical
A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.
CVE-2022-0939 1 Janeczku 1 Calibre-web 2024-11-21 9.9 Critical
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
CVE-2022-0895 1 Microweber 1 Microweber 2024-11-21 9.8 Critical
Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0885 1 Memberhero 1 Member Hero 2024-11-21 9.8 Critical
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
CVE-2022-0871 1 Gogs 1 Gogs 2024-11-21 9.1 Critical
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-0867 1 Reputeinfosystems 1 Pricing Table 2024-11-21 9.8 Critical
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
CVE-2022-0860 2 Cobbler Project, Fedoraproject 2 Cobbler, Fedora 2024-11-21 9.1 Critical
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
CVE-2022-0848 1 Part-db Project 1 Part-db 2024-11-21 9.8 Critical
OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.