Export limit exceeded: 19879 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (19879 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-1120 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.8 Medium |
| Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration. | ||||
| CVE-2022-1111 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 2.4 Low |
| A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages | ||||
| CVE-2022-1105 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 Medium |
| An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled | ||||
| CVE-2022-1103 | 1 Advanced Uploader Project | 1 Advanced Uploader | 2024-11-21 | 8.8 High |
| The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE | ||||
| CVE-2022-1100 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 Medium |
| A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage. | ||||
| CVE-2022-1099 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 Medium |
| Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab | ||||
| CVE-2022-1089 | 1 Wpsheeteditor | 1 Bulk Edit And Create User Profiles - Wp Sheet Editor | 2024-11-21 | 4.8 Medium |
| The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-1062 | 1 Th23 | 1 Th23 Social | 2024-11-21 | 4.8 Medium |
| The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-1051 | 1 2code | 1 Wpqa Builder | 2024-11-21 | 5.4 Medium |
| The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks. | ||||
| CVE-2022-1012 | 2 Linux, Redhat | 5 Linux Kernel, Enterprise Linux, Rhel E4s and 2 more | 2024-11-21 | 8.2 High |
| A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem. | ||||
| CVE-2022-0962 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-0960 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-0946 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0941 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0940 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0938 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0937 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-0930 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.8 Medium |
| File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | ||||
| CVE-2022-0929 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
| XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11. | ||||
| CVE-2022-0926 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.8 Medium |
| File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | ||||