CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2022-2410

    Last Modified: 21 Nov 2024

    The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2409

    Last Modified: 21 Nov 2024

    The Rough Chart WordPress plugin through 1.0.0 does not properly escape chart data label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2398

    Last Modified: 21 Nov 2024

    The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2395

    Last Modified: 21 Nov 2024

    The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 8 Aug 2022
    5.4
    Medium

    CVE-2022-2391

    Last Modified: 21 Nov 2024

    The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.

    Published: 8 Aug 2022
    6.1
    Medium

    CVE-2022-2386

    Last Modified: 21 Nov 2024

    The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2372

    Last Modified: 21 Nov 2024

    The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022
    5.4
    Medium

    CVE-2022-2371

    Last Modified: 21 Nov 2024

    The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.

    Published: 8 Aug 2022
    7.5
    High

    CVE-2022-2367

    Last Modified: 21 Nov 2024

    The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation

    Published: 8 Aug 2022
    7.5
    High

    CVE-2022-2357

    Last Modified: 21 Nov 2024

    The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.

    Published: 8 Aug 2022
    8.8
    High

    CVE-2022-2356

    Last Modified: 23 Jun 2026

    The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

    Published: 8 Aug 2022
    6.5
    Medium

    CVE-2022-2355

    Last Modified: 24 Sept 2025

    The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin

    Published: 8 Aug 2022
    9.8
    Critical

    CVE-2022-2269

    Last Modified: 21 Nov 2024

    The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection

    Published: 8 Aug 2022
    4.9
    Medium

    CVE-2022-2046

    Last Modified: 21 Nov 2024

    The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

    Published: 8 Aug 2022
    6.5
    Medium

    CVE-2022-1323

    Last Modified: 21 Nov 2024

    The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.

    Published: 8 Aug 2022
    5.5
    Medium

    CVE-2022-2708

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_login with the input [email protected]' OR (SELECT 9084 FROM(SELECT COUNT(*),CONCAT(0x7178767871,(SELECT (ELT(9084=9084,1))),0x71767a6271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- dPvW leads to sql injection. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-205833 was assigned to this vulnerability.

    Published: 8 Aug 2022
    6.3
    Medium

    CVE-2022-2707

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/faculty_sched.php. The manipulation of the argument faculty with the input ' OR (SELECT 2078 FROM(SELECT COUNT(*),CONCAT(0x716a717071,(SELECT (ELT(2078=2078,1))),0x717a706a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- uYCM leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205831.

    Published: 8 Aug 2022
    6.3
    Medium

    CVE-2022-2706

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/class_sched.php. The manipulation of the argument class with the input '||(SELECT 0x684d6b6c WHERE 5993=5993 AND (SELECT 2096 FROM(SELECT COUNT(*),CONCAT(0x717a786b71,(SELECT (ELT(2096=2096,1))),0x717a626271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a))||' leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-205830 is the identifier assigned to this vulnerability.

    Published: 8 Aug 2022
    6.3
    Medium

    CVE-2022-2705

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple Student Information System. It has been rated as critical. This issue affects some unknown processing of the file admin/departments/manage_department.php. The manipulation of the argument id with the input -5756%27%20UNION%20ALL%20SELECT%20NULL,database(),user(),NULL,NULL,NULL,NULL--%20- leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205829 was assigned to this vulnerability.

    Published: 8 Aug 2022
    4.3
    Medium

    CVE-2022-2704

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205828.

    Published: 8 Aug 2022
    6.3
    Medium

    CVE-2022-2703

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Gym Management System. It has been classified as critical. This affects an unknown part of the component Exercises Module. The manipulation of the argument exer leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205827.

    Published: 8 Aug 2022
    7.3
    High

    CVE-2022-2702

    Last Modified: 14 Apr 2025

    A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205826 is the identifier assigned to this vulnerability.

    Published: 8 Aug 2022
    3.5
    Low

    CVE-2022-2701

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in SourceCodester Simple E-Learning System. This vulnerability affects unknown code of the file /claire_blake. The manipulation of the argument Bio leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205822 is the identifier assigned to this vulnerability.

    Published: 8 Aug 2022
    4.7
    Medium

    CVE-2022-2700

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the component GET Parameter Handler. The manipulation of the argument day leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205821 was assigned to this vulnerability.

    Published: 8 Aug 2022
    6.3
    Medium

    CVE-2022-2699

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple E-Learning System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /claire_blake. The manipulation of the argument phoneNumber leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205820.

    Published: 8 Aug 2022
    2.6
    Low

    CVE-2022-3629

    Last Modified: 23 Apr 2025

    A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-211930 is the identifier assigned to this vulnerability.

    Published: 8 Aug 2022
    8.7
    High

    CVE-2022-1798

    Last Modified: 21 Apr 2025

    A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.

    Published: 8 Aug 2022
    6.8
    Medium

    CVE-2022-37708

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 8 Aug 2022
    6.3
    Medium

    CVE-2022-2698

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument searchPost leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205819.

    Published: 7 Aug 2022
    6.3
    Medium

    CVE-2022-2697

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple E-Learning System. It has been classified as critical. Affected is an unknown function of the file comment_frame.php. The manipulation of the argument post_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-205818 is the identifier assigned to this vulnerability.

    Published: 7 Aug 2022
    9.8
    Critical

    CVE-2022-37452

    Last Modified: 21 Nov 2024

    Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

    Published: 7 Aug 2022
    —
    Unknown

    CVE-2022-37460

    Last Modified: 6 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 7 Aug 2022
    7.5
    High

    CVE-2022-26979

    Last Modified: 21 Nov 2024

    Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.

    Published: 6 Aug 2022
    7.5
    High

    CVE-2022-27944

    Last Modified: 21 Nov 2024

    Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.

    Published: 6 Aug 2022
    6.3
    Medium

    CVE-2022-2694

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was assigned to this vulnerability.

    Published: 6 Aug 2022
    6.3
    Medium

    CVE-2022-2693

    Last Modified: 15 Apr 2025

    A vulnerability has been found in SourceCodester Electronic Medical Records System and classified as critical. This vulnerability affects unknown code of the file register.php of the component UPDATE Statement Handler. The manipulation of the argument pconsultation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205816.

    Published: 6 Aug 2022
    3.5
    Low

    CVE-2022-2692

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205815.

    Published: 6 Aug 2022
    3.5
    Low

    CVE-2022-2691

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Wedding Hall Booking System. Affected by this issue is some unknown functionality of the file /whbs/?page=manage_account of the component Profile Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205814 is the identifier assigned to this vulnerability.

    Published: 6 Aug 2022
    3.5
    Low

    CVE-2022-2690

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vulnerability is an unknown functionality of the file /whbs/?page=my_bookings of the component Booking Form. The manipulation of the argument Remarks leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205813 was assigned to this vulnerability.

    Published: 6 Aug 2022
    3.5
    Low

    CVE-2022-2689

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an unknown function of the file /whbs/?page=contact_us of the component Contact Page. The manipulation of the argument Message leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205812.

    Published: 6 Aug 2022
    6.3
    Medium

    CVE-2022-2688

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetch_report_credit of the file report.php of the component POST Parameter Handler. The manipulation of the argument from/to leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-205811.

    Published: 6 Aug 2022
    6.3
    Medium

    CVE-2022-2687

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. Affected is an unknown function. The manipulation of the argument user_pass leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-205734 is the identifier assigned to this vulnerability.

    Published: 6 Aug 2022
    3.5
    Low

    CVE-2022-2686

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205725 was assigned to this vulnerability.

    Published: 6 Aug 2022
    7.5
    High

    CVE-2022-37451

    Last Modified: 21 Nov 2024

    Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

    Published: 6 Aug 2022
    7.8
    High

    CVE-2022-32543

    Last Modified: 15 Apr 2025

    An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 5 Aug 2022
    7.8
    High

    CVE-2022-29886

    Last Modified: 15 Apr 2025

    An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 5 Aug 2022
    9.8
    Critical

    CVE-2022-29465

    Last Modified: 15 Apr 2025

    An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 5 Aug 2022
    9.8
    Critical

    CVE-2022-28665

    Last Modified: 15 Apr 2025

    A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable URL-decoding feature that can lead to memory corruption.

    Published: 5 Aug 2022
    9.8
    Critical

    CVE-2022-28664

    Last Modified: 15 Apr 2025

    A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable URL-decoding feature that can lead to memory corruption.

    Published: 5 Aug 2022
    7.5
    High

    CVE-2022-27660

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

    Published: 5 Aug 2022