CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2020-28422

    Last Modified: 21 Nov 2024

    All versions of package git-archive are vulnerable to Command Injection via the exports function.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2020-28438

    Last Modified: 21 Nov 2024

    This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28459

    Last Modified: 21 Nov 2024

    This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2020-28446

    Last Modified: 21 Nov 2024

    The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2020-28443

    Last Modified: 21 Nov 2024

    This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

    Published: 25 Jul 2022
    9.3
    Critical

    CVE-2022-33965

    Last Modified: 6 Mar 2026

    Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

    Published: 25 Jul 2022
    5.4
    Medium

    CVE-2022-21802

    Last Modified: 21 Nov 2024

    The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-2523

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-2514

    Last Modified: 21 Nov 2024

    The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1313

    Last Modified: 21 Nov 2024

    Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    9.6
    Critical

    CVE-2022-1312

    Last Modified: 21 Nov 2024

    Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1311

    Last Modified: 21 Nov 2024

    Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1310

    Last Modified: 21 Nov 2024

    Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    9.6
    Critical

    CVE-2022-1309

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1308

    Last Modified: 21 Nov 2024

    Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    4.3
    Medium

    CVE-2022-1307

    Last Modified: 21 Nov 2024

    Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 25 Jul 2022
    4.3
    Medium

    CVE-2022-1306

    Last Modified: 21 Nov 2024

    Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1305

    Last Modified: 21 Nov 2024

    Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1232

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    4.8
    Medium

    CVE-2022-2341

    Last Modified: 21 Nov 2024

    The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 25 Jul 2022
    4.8
    Medium

    CVE-2022-2340

    Last Modified: 21 Nov 2024

    The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 25 Jul 2022
    5.4
    Medium

    CVE-2022-2299

    Last Modified: 21 Nov 2024

    The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-2240

    Last Modified: 21 Nov 2024

    The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it

    Published: 25 Jul 2022
    4.8
    Medium

    CVE-2022-2239

    Last Modified: 21 Nov 2024

    The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 25 Jul 2022
    7.2
    High

    CVE-2022-2219

    Last Modified: 21 Nov 2024

    The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-2189

    Last Modified: 21 Nov 2024

    The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-2115

    Last Modified: 21 Nov 2024

    The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-2072

    Last Modified: 21 Nov 2024

    The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-2071

    Last Modified: 21 Nov 2024

    The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.

    Published: 25 Jul 2022
    6.5
    Medium

    CVE-2022-1551

    Last Modified: 21 Nov 2024

    The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1539

    Last Modified: 21 Nov 2024

    The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-0899

    Last Modified: 21 Nov 2024

    The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 25 Jul 2022
    5.3
    Medium

    CVE-2022-0594

    Last Modified: 21 Nov 2024

    The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

    Published: 25 Jul 2022
    5.5
    Medium

    CVE-2023-2177

    Last Modified: 18 Mar 2025

    A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed, stream_out is freed which would further be accessed. A local user could use this flaw to crash the system or potentially cause a denial of service.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-29709

    Last Modified: 21 Nov 2024

    CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

    Published: 25 Jul 2022
    8
    High

    CVE-2022-36450

    Last Modified: 21 Nov 2024

    Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2022-36446

    Last Modified: 21 Nov 2024

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    Published: 25 Jul 2022
    8.6
    High

    CVE-2022-36444

    Last Modified: 21 Nov 2024

    An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticated attacker (with network access to the admin interface) to disrupt system availability or potentially compromise the confidentiality and integrity of the system.

    Published: 25 Jul 2022
    6.3
    Medium

    CVE-2017-20145

    Last Modified: 15 Apr 2025

    A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Jul 2022
    7.2
    High

    CVE-2022-34965

    Last Modified: 21 Nov 2024

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior of the application as it only allows authenticated admins to upload files.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-1314

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Jul 2022
    8.6
    High

    CVE-2020-7677

    Last Modified: 21 Nov 2024

    This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

    Published: 25 Jul 2022
    7.8
    High

    CVE-2022-2522

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

    Published: 25 Jul 2022
    —
    Unknown

    CVE-2022-2530

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-26307

    Last Modified: 21 Nov 2024

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-26305

    Last Modified: 21 Nov 2024

    An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could therefore create an arbitrary certificate with a serial number and an issuer string identical to a trusted certificate which LibreOffice would present as belonging to the trusted author, potentially leading to the user to execute arbitrary code contained in macros improperly trusted. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-26306

    Last Modified: 21 Nov 2024

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-34749

    Last Modified: 21 Nov 2024

    In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

    Published: 25 Jul 2022
    6.3
    Medium

    CVE-2017-20144

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Anvsoft PDFMate PDF Converter Pro 1.7.5.0 and classified as critical. The manipulation leads to memory corruption. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Jul 2022
    7.5
    High

    CVE-2022-24294

    Last Modified: 21 Nov 2024

    A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular expression evaluation to use excessive resources to attempt a match. This issue affects Apache MXNet versions prior to 1.9.1.

    Published: 24 Jul 2022