CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-25121

    Last Modified: 21 Nov 2024

    The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating

    Published: 20 Jun 2022
    6.1
    Medium

    CVE-2021-25104

    Last Modified: 21 Nov 2024

    The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue

    Published: 20 Jun 2022
    4.8
    Medium

    CVE-2021-25088

    Last Modified: 21 Nov 2024

    The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 20 Jun 2022
    7.9
    High

    CVE-2022-1823

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code, through not correctly checking the integrity of the configuration file.

    Published: 20 Jun 2022
    7.9
    High

    CVE-2022-1824

    Last Modified: 21 Nov 2024

    An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.

    Published: 20 Jun 2022
    6.1
    Medium

    CVE-2022-31734

    Last Modified: 21 Nov 2024

    Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affected firmware is prior to 12.2(50)SY released in 2011, and Cisco Catalyst 2940 Series Switches have been retired since January 2015

    Published: 20 Jun 2022
    6.1
    Medium

    CVE-2022-2130

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

    Published: 20 Jun 2022
    8.8
    High

    CVE-2022-26669

    Last Modified: 21 Nov 2024

    ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.

    Published: 20 Jun 2022
    7.3
    High

    CVE-2022-26668

    Last Modified: 21 Nov 2024

    ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.

    Published: 20 Jun 2022
    6.2
    Medium

    CVE-2022-21742

    Last Modified: 21 Nov 2024

    Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services.

    Published: 20 Jun 2022
    7.5
    High

    CVE-2021-45918

    Last Modified: 21 Nov 2024

    NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service.

    Published: 20 Jun 2022
    6.3
    Medium

    CVE-2017-20064

    Last Modified: 15 Apr 2025

    A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection. The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    6.3
    Medium

    CVE-2017-20063

    Last Modified: 15 Apr 2025

    A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File Upload. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    5
    Medium

    CVE-2017-20062

    Last Modified: 15 Apr 2025

    A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    4.3
    Medium

    CVE-2017-20061

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    3.5
    Low

    CVE-2017-20060

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to basic cross site scripting (Persistent). It is possible to initiate the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    3.5
    Low

    CVE-2017-20059

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input </title><img src=no onerror=alert(1)> leads to basic cross site scripting (Persistent). The attack may be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    4.3
    Medium

    CVE-2017-20058

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    4.3
    Medium

    CVE-2017-20057

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 20 Jun 2022
    9.8
    Critical

    CVE-2022-2023

    Last Modified: 21 Nov 2024

    Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.

    Published: 20 Jun 2022
    6.1
    Medium

    CVE-2022-39842

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.

    Published: 20 Jun 2022
    9.8
    Critical

    CVE-2022-22980

    Last Modified: 21 Nov 2024

    A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

    Published: 20 Jun 2022
    9.6
    Critical

    CVE-2022-25772

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript

    Published: 20 Jun 2022
    5.3
    Medium

    CVE-2022-31062

    Last Modified: 23 Apr 2025

    ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

    Published: 20 Jun 2022
    6.5
    Medium

    CVE-2022-2134

    Last Modified: 21 Nov 2024

    Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

    Published: 20 Jun 2022
    9.8
    Critical

    CVE-2022-34005

    Last Modified: 21 Nov 2024

    An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue 1). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.

    Published: 19 Jun 2022
    7.8
    High

    CVE-2022-34006

    Last Modified: 21 Nov 2024

    An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITY\SYSTEM, aka NX-I674 (sub-issue 2). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.

    Published: 19 Jun 2022
    6.5
    Medium

    CVE-2022-23071

    Last Modified: 21 Nov 2024

    In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.

    Published: 19 Jun 2022
    5.3
    Medium

    CVE-2014-125025

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in FFmpeg 2.0. This affects the function decode_pulses. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    7.3
    High

    CVE-2014-125024

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decode_frame. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    5.3
    Medium

    CVE-2014-125023

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the function truemotion1_decode_header of the component Truemotion1 Handler. The manipulation leads to memory corruption. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    5.3
    Medium

    CVE-2014-125022

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function shorten_decode_frame of the component Bitstream Buffer. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    5.3
    Medium

    CVE-2014-125021

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function cmv_process_header. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    7.3
    High

    CVE-2014-125020

    Last Modified: 15 Apr 2025

    A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vulnerability affects the function decode_update_thread_context. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    5.3
    Medium

    CVE-2014-125019

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_nal_unit of the component Slice Segment Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    5.3
    Medium

    CVE-2014-125018

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in FFmpeg 2.0. Affected by this issue is the function decode_slice_header. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

    Published: 19 Jun 2022
    —
    Unknown

    CVE-2022-29895

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Jun 2022
    —
    Unknown

    CVE-2022-33976

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Jun 2022
    6.5
    Medium

    CVE-2022-34000

    Last Modified: 21 Nov 2024

    libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.

    Published: 19 Jun 2022
    7.8
    High

    CVE-2022-2129

    Last Modified: 3 Nov 2025

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

    Published: 19 Jun 2022
    7.8
    High

    CVE-2022-2124

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

    Published: 19 Jun 2022
    7.8
    High

    CVE-2022-2125

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 19 Jun 2022
    7.8
    High

    CVE-2022-2126

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

    Published: 19 Jun 2022
    7.3
    High

    CVE-2014-125017

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022
    5.3
    Medium

    CVE-2014-125016

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0. It has been rated as problematic. This issue affects the function ff_init_buffer_info of the file utils.c. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022
    7.3
    High

    CVE-2014-125015

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022
    5.3
    Medium

    CVE-2014-125014

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in FFmpeg 2.0. Affected by this vulnerability is an unknown functionality of the component HEVC Video Decoder. The manipulation leads to memory corruption. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022
    5.3
    Medium

    CVE-2014-125013

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function msrle_decode_frame of the file libavcodec/msrle.c. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022
    5.3
    Medium

    CVE-2014-125012

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is an unknown function of the file libavcodec/dxtroy.c. The manipulation leads to integer coercion error. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022
    5.3
    Medium

    CVE-2014-125011

    Last Modified: 15 Apr 2025

    A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the function decode_frame of the file libavcodec/ansi.c. The manipulation leads to integer coercion error. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.

    Published: 18 Jun 2022