CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-33093

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32131

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32130

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_resume/total/nature.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32129

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/safety/trade.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32128

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32126

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32127

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32125

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-32124

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2021-41432

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.

    Published: 22 Jun 2022
    —
    Unknown

    CVE-2022-29301

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-20660. Reason: This candidate is a reservation duplicate of CVE-2021-20660. Notes: All CVE users should reference CVE-2021-20660 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Jun 2022
    —
    Unknown

    CVE-2022-29299

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-20660. Reason: This candidate is a reservation duplicate of CVE-2021-20660. Notes: All CVE users should reference CVE-2021-20660 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Jun 2022
    3.5
    Low

    CVE-2022-32159

    Last Modified: 21 Nov 2024

    In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

    Published: 22 Jun 2022
    4.3
    Medium

    CVE-2022-23081

    Last Modified: 21 Nov 2024

    In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.

    Published: 22 Jun 2022
    9.8
    Critical

    CVE-2022-31361

    Last Modified: 21 Nov 2024

    Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 22 Jun 2022
    8.8
    High

    CVE-2022-31362

    Last Modified: 21 Nov 2024

    Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 22 Jun 2022
    5
    Medium

    CVE-2022-23080

    Last Modified: 21 Nov 2024

    In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.

    Published: 22 Jun 2022
    —
    Unknown

    CVE-2022-2176

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34295

    Last Modified: 21 Nov 2024

    totd before 1.5.3 does not properly randomize mesg IDs.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34213

    Last Modified: 21 Nov 2024

    Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 22 Jun 2022
    5.7
    Medium

    CVE-2022-34212

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34211

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34210

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34209

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified URL.

    Published: 22 Jun 2022
    4.3
    Medium

    CVE-2022-34208

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34207

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.

    Published: 22 Jun 2022
    4.3
    Medium

    CVE-2022-34206

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34205

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.

    Published: 22 Jun 2022
    4.3
    Medium

    CVE-2022-34204

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

    Published: 22 Jun 2022
    8.8
    High

    CVE-2022-34203

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34202

    Last Modified: 21 Nov 2024

    Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34201

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

    Published: 22 Jun 2022
    8.8
    High

    CVE-2022-34200

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL.

    Published: 22 Jun 2022
    6.5
    Medium

    CVE-2022-34199

    Last Modified: 21 Nov 2024

    Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34198

    Last Modified: 21 Nov 2024

    Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34197

    Last Modified: 21 Nov 2024

    Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34196

    Last Modified: 21 Nov 2024

    Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34195

    Last Modified: 21 Nov 2024

    Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34194

    Last Modified: 21 Nov 2024

    Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Readonly Text parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34193

    Last Modified: 21 Nov 2024

    Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34192

    Last Modified: 21 Nov 2024

    Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: Parameter choice, and Ontrack: SingleParameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34191

    Last Modified: 21 Nov 2024

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34190

    Last Modified: 21 Nov 2024

    Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of List maven artifact versions parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34189

    Last Modified: 21 Nov 2024

    Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34188

    Last Modified: 21 Nov 2024

    Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34187

    Last Modified: 21 Nov 2024

    Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34186

    Last Modified: 21 Nov 2024

    Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34185

    Last Modified: 21 Nov 2024

    Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34184

    Last Modified: 21 Nov 2024

    Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022
    5.4
    Medium

    CVE-2022-34183

    Last Modified: 21 Nov 2024

    Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 22 Jun 2022