Export limit exceeded: 18671 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 18671 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18671 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-1051 | 1 2code | 1 Wpqa Builder | 2024-11-21 | 5.4 Medium |
| The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks. | ||||
| CVE-2022-1012 | 2 Linux, Redhat | 5 Linux Kernel, Enterprise Linux, Rhel E4s and 2 more | 2024-11-21 | 8.2 High |
| A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem. | ||||
| CVE-2022-0962 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-0960 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-0946 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0941 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0940 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0938 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4. | ||||
| CVE-2022-0937 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-0930 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.8 Medium |
| File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | ||||
| CVE-2022-0929 | 1 Microweber | 1 Microweber | 2024-11-21 | 6.1 Medium |
| XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11. | ||||
| CVE-2022-0926 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.8 Medium |
| File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | ||||
| CVE-2022-0880 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. | ||||
| CVE-2022-0873 | 1 Codeasily | 1 Gmedia Gallery | 2024-11-21 | 4.8 Medium |
| The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed | ||||
| CVE-2022-0867 | 1 Reputeinfosystems | 1 Pricing Table | 2024-11-21 | 9.8 Critical |
| The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users | ||||
| CVE-2022-0703 | 1 Gd-mylist Project | 1 Gd-mylist | 2024-11-21 | 4.8 Medium |
| The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-0702 | 1 Unboxinteractive | 1 Petfinder-listings | 2024-11-21 | 4.8 Medium |
| The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-0701 | 1 Seo-301-meta Project | 1 Seo-301-meta | 2024-11-21 | 4.8 Medium |
| The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-0700 | 1 Chrsinteractive | 1 Simple Tracking | 2024-11-21 | 4.8 Medium |
| The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-0684 | 1 Wp Home Page Menu Project | 1 Wp Home Page Menu | 2024-11-21 | 4.8 Medium |
| The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||