CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2022-1569

    Last Modified: 21 Nov 2024

    The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

    Published: 6 Jun 2022
    4.8
    Medium

    CVE-2022-1541

    Last Modified: 21 Nov 2024

    The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 6 Jun 2022
    5.4
    Medium

    CVE-2022-1506

    Last Modified: 21 Nov 2024

    The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

    Published: 6 Jun 2022
    4.8
    Medium

    CVE-2022-1469

    Last Modified: 21 Nov 2024

    The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

    Published: 6 Jun 2022
    6.5
    Medium

    CVE-2022-1424

    Last Modified: 21 Nov 2024

    The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

    Published: 6 Jun 2022
    6.5
    Medium

    CVE-2022-1422

    Last Modified: 21 Nov 2024

    The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

    Published: 6 Jun 2022
    4.3
    Medium

    CVE-2022-1421

    Last Modified: 21 Nov 2024

    The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

    Published: 6 Jun 2022
    4.8
    Medium

    CVE-2022-1394

    Last Modified: 21 Nov 2024

    The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-1241

    Last Modified: 21 Nov 2024

    The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-1005

    Last Modified: 21 Nov 2024

    The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

    Published: 6 Jun 2022
    9.8
    Critical

    CVE-2022-0788

    Last Modified: 5 Dec 2024

    The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users

    Published: 6 Jun 2022
    6.5
    Medium

    CVE-2022-0779

    Last Modified: 21 Nov 2024

    The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads

    Published: 6 Jun 2022
    9.1
    Critical

    CVE-2022-1996

    Last Modified: 21 Nov 2024

    Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

    Published: 6 Jun 2022
    7.5
    High

    CVE-2022-32275

    Last Modified: 21 Nov 2024

    Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-32479

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-32494

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-32495

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-32496

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-32497

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Jun 2022
    7.5
    High

    CVE-2022-1708

    Last Modified: 21 Nov 2024

    A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus, if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability.

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-32472

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 6 Jun 2022
    5.5
    Medium

    CVE-2022-31030

    Last Modified: 21 Nov 2024

    containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd's CRI implementation; `ExecSync` may be used when running probes or when executing processes via an "exec" facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.

    Published: 6 Jun 2022
    8.8
    High

    CVE-2022-32291

    Last Modified: 21 Nov 2024

    In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.

    Published: 5 Jun 2022
    6.3
    Medium

    CVE-2017-20017

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in The Next Generation of Genealogy Sitebuilding up to 11.1.0. This issue affects some unknown processing of the file /timeline2.php. The manipulation of the argument primaryID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 5 Jun 2022
    3.5
    Low

    CVE-2020-36544

    Last Modified: 15 Apr 2025

    A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of the component Search Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Jun 2022
    6.3
    Medium

    CVE-2020-36543

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in SialWeb CMS. This affects an unknown part of the file /about.php. The manipulation of the argument Id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Jun 2022
    5.3
    Medium

    CVE-2019-25063

    Last Modified: 15 Apr 2025

    A vulnerability was found in Sricam IP CCTV Camera. It has been classified as critical. Affected is an unknown function of the component Device Viewer. The manipulation leads to memory corruption. Local access is required to approach this attack.

    Published: 4 Jun 2022
    5.3
    Medium

    CVE-2019-25062

    Last Modified: 15 Apr 2025

    A vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processing of the component Device Viewer. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 4 Jun 2022
    9.8
    Critical

    CVE-2022-26134

    Last Modified: 24 Oct 2025

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

    Published: 3 Jun 2022
    8.8
    High

    CVE-2022-1703

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.

    Published: 3 Jun 2022
    5.3
    Medium

    CVE-2022-29784

    Last Modified: 21 Nov 2024

    PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.

    Published: 3 Jun 2022
    8.8
    High

    CVE-2022-29778

    Last Modified: 21 Nov 2024

    D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php

    Published: 3 Jun 2022
    6.5
    Medium

    CVE-2022-29773

    Last Modified: 21 Nov 2024

    An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and below allows attackers to access arbitrary scopes if no allowed scopes are specifically set.

    Published: 3 Jun 2022
    9
    Critical

    CVE-2022-21122

    Last Modified: 21 Nov 2024

    The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

    Published: 3 Jun 2022
    5.4
    Medium

    CVE-2022-29770

    Last Modified: 21 Nov 2024

    XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.

    Published: 3 Jun 2022
    8.1
    High

    CVE-2022-24065

    Last Modified: 21 Nov 2024

    The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

    Published: 3 Jun 2022
    6.8
    Medium

    CVE-2021-43271

    Last Modified: 21 Nov 2024

    Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS authentication) logs usernames and passwords if either is entered incorrectly. If a user enters an incorrect username and/or password when logging into the WebUI, these attempted credentials are included in an error message that is logged in the WebUI log file. A log entry does not appear if the username and password provided correctly match a valid set of credentials. This also does not happen if AppResponse is configured to use SAML authentication. The WebUI log file is included in subsequent diagnostic system dumps that are generated. (Only users with Full Control access to the System Configuration permission can generate system dumps. By default, only System Administrators have Full Control access to the System Configuration permission.)

    Published: 3 Jun 2022
    7.3
    High

    CVE-2020-36542

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 3 Jun 2022
    7.3
    High

    CVE-2020-36541

    Last Modified: 15 Apr 2025

    A vulnerability was found in Demokratian. It has been rated as critical. Affected by this issue is some unknown functionality of the file basicos_php/genera_select.php. The manipulation of the argument id_provincia with the input -1%20union%20all%20select%201,2,3,4,database() leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36540

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in Neetai Tech. Affected is an unknown function of the file /product.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36539

    Last Modified: 15 Apr 2025

    A vulnerability was found in Lógico y Creativo 1.0 and classified as critical. This issue affects some unknown processing. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36538

    Last Modified: 15 Apr 2025

    A vulnerability was found in Eatan CMS. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The attack can be launched remotely.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36537

    Last Modified: 15 Apr 2025

    A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36536

    Last Modified: 15 Apr 2025

    A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36535

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in MINMAX. This affects an unknown part of the file /newsDia.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.

    Published: 3 Jun 2022
    4.3
    Medium

    CVE-2020-36534

    Last Modified: 15 Apr 2025

    A vulnerability was found in easyii CMS. It has been classified as problematic. Affected is an unknown function of the file /admin/sign/out. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Jun 2022
    3.7
    Low

    CVE-2020-36533

    Last Modified: 15 Apr 2025

    A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the JSON Web Token Handler. The manipulation leads to weak authentication. The attack may be initiated remotely.

    Published: 3 Jun 2022
    4.3
    Medium

    CVE-2020-36532

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Klapp App and classified as problematic. This vulnerability affects unknown code of the component Authorization. The manipulation leads to information disclosure (Credentials). The attack can be initiated remotely. It is recommended to upgrade the affected app.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36531

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.

    Published: 3 Jun 2022
    6.3
    Medium

    CVE-2020-36530

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely.

    Published: 3 Jun 2022