CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-29286

    Last Modified: 21 Nov 2024

    Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27937

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27936

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27935

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27934

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.

    Published: 17 Jul 2022
    8.2
    High

    CVE-2022-27933

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27932

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27931

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

    Published: 17 Jul 2022
    5.9
    Medium

    CVE-2022-27930

    Last Modified: 21 Nov 2024

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27929

    Last Modified: 21 Nov 2024

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-27928

    Last Modified: 21 Nov 2024

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-26657

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

    Published: 17 Jul 2022
    8.2
    High

    CVE-2022-26656

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-26655

    Last Modified: 21 Nov 2024

    Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a software abort via a gateway call into Teams.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-26654

    Last Modified: 21 Nov 2024

    Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP.

    Published: 17 Jul 2022
    5.3
    Medium

    CVE-2022-30622

    Last Modified: 21 Nov 2024

    Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_username_passwd.cmd - The server loads the request clearly by default. Disclosure of hard-coded credit information within the JS code sent to the customer within the Login.js file is a strong user (which is not documented) and also the password, which allow for super-user access. Username: chcadmin, Password: chcpassword.

    Published: 17 Jul 2022
    5.3
    Medium

    CVE-2022-25357

    Last Modified: 21 Nov 2024

    Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.

    Published: 17 Jul 2022
    6.5
    Medium

    CVE-2022-31260

    Last Modified: 21 Nov 2024

    In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.

    Published: 17 Jul 2022
    7.8
    High

    CVE-2022-35861

    Last Modified: 21 Nov 2024

    pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a Python version string in .python-version to execute shims under their control. (Shims are executables that pass a command along to a specific version of pyenv. The version string is used to construct the path to the command, and there is no validation of whether the version specified is a valid version. Thus, relative path traversal can occur.)

    Published: 17 Jul 2022
    8.8
    High

    CVE-2022-32320

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.

    Published: 17 Jul 2022
    4.9
    Medium

    CVE-2022-2222

    Last Modified: 21 Nov 2024

    The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2194

    Last Modified: 21 Nov 2024

    The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    6.1
    Medium

    CVE-2022-2187

    Last Modified: 21 Nov 2024

    The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2186

    Last Modified: 21 Nov 2024

    The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    6.1
    Medium

    CVE-2022-2173

    Last Modified: 21 Nov 2024

    The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2169

    Last Modified: 21 Nov 2024

    The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    6.1
    Medium

    CVE-2022-2168

    Last Modified: 21 Mar 2025

    The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2151

    Last Modified: 21 Nov 2024

    The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2149

    Last Modified: 21 Nov 2024

    The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2148

    Last Modified: 21 Nov 2024

    The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    6.1
    Medium

    CVE-2022-2146

    Last Modified: 21 Nov 2024

    The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting

    Published: 17 Jul 2022
    4.3
    Medium

    CVE-2022-2144

    Last Modified: 21 Nov 2024

    The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack

    Published: 17 Jul 2022
    5.3
    Medium

    CVE-2022-2133

    Last Modified: 21 Nov 2024

    The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2118

    Last Modified: 21 Nov 2024

    The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2114

    Last Modified: 21 Nov 2024

    The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2100

    Last Modified: 21 Nov 2024

    The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Jul 2022
    4.8
    Medium

    CVE-2022-2099

    Last Modified: 21 Nov 2024

    The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

    Published: 17 Jul 2022
    6.1
    Medium

    CVE-2022-2090

    Last Modified: 21 Nov 2024

    The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting

    Published: 17 Jul 2022
    6.1
    Medium

    CVE-2022-1933

    Last Modified: 21 Nov 2024

    The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

    Published: 17 Jul 2022
    8.8
    High

    CVE-2022-1672

    Last Modified: 21 Nov 2024

    The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

    Published: 17 Jul 2022
    7.5
    High

    CVE-2021-24655

    Last Modified: 21 Nov 2024

    The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.

    Published: 17 Jul 2022
    4
    Medium

    CVE-2020-7641

    Last Modified: 21 Nov 2024

    This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

    Published: 17 Jul 2022
    4.3
    Medium

    CVE-2015-10003

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2020-16093

    Last Modified: 21 Nov 2024

    In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-33903

    Last Modified: 21 Nov 2024

    Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-4899

    Last Modified: 18 Feb 2025

    A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

    Published: 17 Jul 2022
    7.2
    High

    CVE-2022-36126

    Last Modified: 21 Nov 2024

    An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.

    Published: 16 Jul 2022
    9.8
    Critical

    CVE-2021-36711

    Last Modified: 21 Nov 2024

    WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.

    Published: 16 Jul 2022
    7.5
    High

    CVE-2021-34538

    Last Modified: 21 Nov 2024

    Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

    Published: 16 Jul 2022
    6.3
    Medium

    CVE-2017-20138

    Last Modified: 15 Apr 2025

    A vulnerability was found in Itech Auction Script 6.49. It has been classified as critical. This affects an unknown part of the file /mcategory.php. The manipulation of the argument mcid with the input 4' AND 1734=1734 AND 'Ggks'='Ggks leads to sql injection (Blind). It is possible to initiate the attack remotely.

    Published: 16 Jul 2022