Search Results (349719 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-1936 1 Gitlab 1 Gitlab 2024-11-21 6.5 Medium
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured
CVE-2022-1935 1 Gitlab 1 Gitlab 2024-11-21 6.5 Medium
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured
CVE-2022-1934 1 Mruby 1 Mruby 2024-11-21 7.8 High
Use After Free in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-1933 1 Collect And Deliver Interface For Woocommerce Project 1 Collect And Deliver Interface For Woocommerce 2024-11-21 6.1 Medium
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
CVE-2022-1932 1 Rezgo 1 Rezgo Online Booking 2024-11-21 6.1 Medium
The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file
CVE-2022-1931 1 Trudesk Project 1 Trudesk 2024-11-21 8.1 High
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1930 1 Ethereum 1 Eth-account 2024-11-21 5.9 Medium
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method
CVE-2022-1929 1 Devcert Project 1 Devcert 2024-11-21 5.9 Medium
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
CVE-2022-1928 1 Gitea 1 Gitea 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
CVE-2022-1927 4 Apple, Fedoraproject, Redhat and 1 more 5 Macos, Fedora, Enterprise Linux and 2 more 2024-11-21 7.8 High
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
CVE-2022-1926 1 Trudesk Project 1 Trudesk 2024-11-21 4.9 Medium
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1919 1 Google 1 Chrome 2024-11-21 8.8 High
Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-1916 1 Pluginus 1 Woot 2024-11-21 6.1 Medium
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting
CVE-2022-1915 1 Wpreviewslider 1 Wp Zillow Review Slider 2024-11-21 4.8 Medium
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)
CVE-2022-1914 1 Clean-contact Project 1 Clean-contact 2024-11-21 4.3 Medium
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well
CVE-2022-1913 1 Add Post Url Project 1 Add Post Url 2024-11-21 4.3 Medium
The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
CVE-2022-1910 1 Averta 1 Shortcodes And Extra Features For Phlox Theme 2024-11-21 6.1 Medium
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
CVE-2022-1909 1 Organizr 1 Organizr 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.
CVE-2022-1908 1 Libmobi Project 1 Libmobi 2024-11-21 8.1 High
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
CVE-2022-1907 1 Libmobi Project 1 Libmobi 2024-11-21 8.1 High
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.