CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-1474

    Last Modified: 21 Nov 2024

    The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-1220

    Last Modified: 21 Nov 2024

    The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2022-1057

    Last Modified: 21 Nov 2024

    The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

    Published: 11 Jul 2022
    5.3
    Medium

    CVE-2022-33911

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-33173

    Last Modified: 21 Nov 2024

    An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2021-41396

    Last Modified: 21 Nov 2024

    Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS attack.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-30792

    Last Modified: 21 Nov 2024

    In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-30791

    Last Modified: 21 Nov 2024

    In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2022-2302

    Last Modified: 21 Nov 2024

    Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.

    Published: 11 Jul 2022
    5.5
    Medium

    CVE-2022-1794

    Last Modified: 21 Nov 2024

    The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-29926

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation in Cybozu, Inc. showed that it was not a vulnerability. Notes: https://jvn.jp/en/jp/JVN14077132

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-2368

    Last Modified: 25 Feb 2026

    Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-35416

    Last Modified: 21 Nov 2024

    H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31588

    Last Modified: 21 Nov 2024

    The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31587

    Last Modified: 21 Nov 2024

    The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31586

    Last Modified: 21 Nov 2024

    The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31585

    Last Modified: 21 Nov 2024

    The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31584

    Last Modified: 21 Nov 2024

    The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31583

    Last Modified: 21 Nov 2024

    The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31582

    Last Modified: 21 Nov 2024

    The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31581

    Last Modified: 21 Nov 2024

    The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31580

    Last Modified: 21 Nov 2024

    The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31579

    Last Modified: 21 Nov 2024

    The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-31578

    Last Modified: 21 Nov 2024

    The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31577

    Last Modified: 21 Nov 2024

    The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31576

    Last Modified: 21 Nov 2024

    The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31575

    Last Modified: 21 Nov 2024

    The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31574

    Last Modified: 21 Nov 2024

    The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31573

    Last Modified: 21 Nov 2024

    The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31572

    Last Modified: 21 Nov 2024

    The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31571

    Last Modified: 21 Nov 2024

    The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2022-31570

    Last Modified: 21 Nov 2024

    The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-31569

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that no specific affected product had been identified. Notes: none

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31568

    Last Modified: 21 Nov 2024

    The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31567

    Last Modified: 21 Nov 2024

    The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    8.6
    High

    CVE-2022-31566

    Last Modified: 21 Nov 2024

    The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31565

    Last Modified: 21 Nov 2024

    The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31564

    Last Modified: 21 Nov 2024

    The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31563

    Last Modified: 21 Nov 2024

    The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31562

    Last Modified: 21 Nov 2024

    The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31561

    Last Modified: 21 Nov 2024

    The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31560

    Last Modified: 21 Nov 2024

    The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31559

    Last Modified: 21 Nov 2024

    The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31558

    Last Modified: 21 Nov 2024

    The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31557

    Last Modified: 21 Nov 2024

    The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31556

    Last Modified: 21 Nov 2024

    The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31555

    Last Modified: 21 Nov 2024

    The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31554

    Last Modified: 21 Nov 2024

    The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31553

    Last Modified: 21 Nov 2024

    The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    9.3
    Critical

    CVE-2022-31552

    Last Modified: 21 Nov 2024

    The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022