Export limit exceeded: 50721 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50740 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-1850 | 1 Filegator | 1 Filegator | 2024-11-21 | 8.1 High |
| Path Traversal in GitHub repository filegator/filegator prior to 7.8.0. | ||||
| CVE-2022-1849 | 1 Filegator | 1 Filegator | 2024-11-21 | 5.4 Medium |
| Session Fixation in GitHub repository filegator/filegator prior to 7.8.0. | ||||
| CVE-2022-1848 | 1 Erudika | 1 Para | 2024-11-21 | 5.3 Medium |
| Business Logic Errors in GitHub repository erudika/para prior to 1.45.11. | ||||
| CVE-2022-1841 | 1 Zephyrproject | 1 Zephyr | 2024-11-21 | 7.2 High |
| In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-bounds write a byte zero. | ||||
| CVE-2022-1825 | 1 Collectiveaccess | 1 Providence | 2024-11-21 | 5.4 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. | ||||
| CVE-2022-1816 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 3.5 Low |
| A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public. | ||||
| CVE-2022-1814 | 1 Wp Admin Style Project | 1 Wp Admin Style | 2024-11-21 | 4.8 Medium |
| The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | ||||
| CVE-2022-1813 | 1 Rengine Project | 1 Rengine | 2024-11-21 | 9.8 Critical |
| OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. | ||||
| CVE-2022-1811 | 1 Publify Project | 1 Publify | 2024-11-21 | 5.4 Medium |
| Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. | ||||
| CVE-2022-1810 | 1 Publify Project | 1 Publify | 2024-11-21 | 4.3 Medium |
| Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9. | ||||
| CVE-2022-1809 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.8 High |
| Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0. | ||||
| CVE-2022-1806 | 1 Rtx Project | 1 Rtx | 2024-11-21 | 6.1 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18. | ||||
| CVE-2022-1803 | 1 Trudesk Project | 1 Trudesk | 2024-11-21 | 6.9 Medium |
| Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2. | ||||
| CVE-2022-1800 | 1 Soflyy | 1 Export Any Wordpress Data To Xml\/csv | 2024-11-21 | 7.2 High |
| The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability. | ||||
| CVE-2022-1796 | 1 Vim | 1 Vim | 2024-11-21 | 7.8 High |
| Use After Free in GitHub repository vim/vim prior to 8.2.4979. | ||||
| CVE-2022-1795 | 1 Gpac | 1 Gpac | 2024-11-21 | 9.8 Critical |
| Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV. | ||||
| CVE-2022-1793 | 1 Private Files Project | 1 Private Files | 2024-11-21 | 4.3 Medium |
| The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public | ||||
| CVE-2022-1792 | 1 Quick Subscribe Project | 1 Quick Subscribe | 2024-11-21 | 5.4 Medium |
| The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them | ||||
| CVE-2022-1791 | 1 One Click Plugin Updater Project | 1 One Click Plugin Updater | 2024-11-21 | 8.1 High |
| The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check. | ||||
| CVE-2022-1790 | 1 New User Email Set Up Project | 1 New User Email Set Up | 2024-11-21 | 6.5 Medium |
| The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | ||||