Search Results (30282 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0591 1 Subtlewebinc 1 Formcraft3 2024-11-21 9.1 Critical
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
CVE-2022-0570 1 Mruby 1 Mruby 2024-11-21 9.8 Critical
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
CVE-2022-0567 2 Ovn, Redhat 2 Ovn-kubernetes, Openshift 2024-11-21 9.1 Critical
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.
CVE-2022-0559 2 Fedoraproject, Radare 2 Fedora, Radare2 2024-11-21 9.8 Critical
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0541 1 Flothemes 1 Flo-launch 2024-11-21 9.8 Critical
The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.
CVE-2022-0540 1 Atlassian 3 Jira Data Center, Jira Server, Jira Service Management 2024-11-21 9.8 Critical
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.
CVE-2022-0525 1 Mruby 1 Mruby 2024-11-21 9.1 Critical
Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-0482 1 Easyappointments 1 Easyappointments 2024-11-21 9.1 Critical
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CVE-2022-0479 1 Sygnoos 1 Popup Builder 2024-11-21 9.8 Critical
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link
CVE-2022-0466 1 Google 1 Chrome 2024-11-21 9.6 Critical
Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
CVE-2022-0452 1 Google 1 Chrome 2024-11-21 9.6 Critical
Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2022-0441 1 Stylemixthemes 1 Masterstudy Lms 2024-11-21 9.8 Critical
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CVE-2022-0434 1 A3rev 1 Page View Count 2024-11-21 9.8 Critical
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks
CVE-2022-0412 1 Templateinvaders 1 Ti Woocommerce Wishlist 2024-11-21 9.8 Critical
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
CVE-2022-0401 1 W-zip Project 1 W-zip 2024-11-21 9.8 Critical
Path Traversal in NPM w-zip prior to 1.0.12.
CVE-2022-0362 1 Showdoc 1 Showdoc 2024-11-21 9.8 Critical
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
CVE-2022-0349 1 Wpdeveloper 1 Notificationx 2024-11-21 9.8 Critical
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
CVE-2022-0342 1 Zyxel 46 Atp100, Atp100 Firmware, Atp100w and 43 more 2024-11-21 9.8 Critical
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
CVE-2022-0339 1 Janeczku 1 Calibre-web 2024-11-21 9.8 Critical
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
CVE-2022-0332 1 Moodle 1 Moodle 2024-11-21 9.8 Critical
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.