CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-29499

    Last Modified: 3 Nov 2025

    The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

    Published: 26 Apr 2022
    5.5
    Medium

    CVE-2022-34494

    Last Modified: 21 Nov 2024

    rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

    Published: 26 Apr 2022
    5.5
    Medium

    CVE-2023-1981

    Last Modified: 3 Nov 2025

    A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-24706

    Last Modified: 28 Oct 2025

    In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

    Published: 26 Apr 2022
    7.5
    High

    CVE-2021-3523

    Last Modified: 21 Nov 2024

    A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

    Published: 26 Apr 2022
    5.3
    Medium

    CVE-2022-24880

    Last Modified: 23 Apr 2025

    flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.g. by submitting an having an empty form). If implementing users were checking the return value to be **False**, the captcha verification check could be bypassed. Version 1.2.1 fixes the issue. Users can workaround the issue by not explicitly checking that the value is False. Checking the return value less explicitly should still work.

    Published: 25 Apr 2022
    7.5
    High

    CVE-2021-35250

    Last Modified: 21 Nov 2024

    A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

    Published: 25 Apr 2022
    8.1
    High

    CVE-2022-25866

    Last Modified: 21 Nov 2024

    The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

    Published: 25 Apr 2022
    6
    Medium

    CVE-2022-29419

    Last Modified: 20 Feb 2025

    SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with a low role like a subscriber or higher.

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-29418

    Last Modified: 20 Feb 2025

    Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2022-29417

    Last Modified: 20 Feb 2025

    Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.

    Published: 25 Apr 2022
    4.9
    Medium

    CVE-2022-0477

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2022-28290

    Last Modified: 21 Nov 2024

    Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-1396

    Last Modified: 21 Nov 2024

    The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed

    Published: 25 Apr 2022
    7.5
    High

    CVE-2022-1392

    Last Modified: 21 Nov 2024

    The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-1391

    Last Modified: 21 Nov 2024

    The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-1390

    Last Modified: 21 Nov 2024

    The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-1228

    Last Modified: 21 Nov 2024

    The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" field, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-1156

    Last Modified: 21 Nov 2024

    The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-1153

    Last Modified: 17 Mar 2025

    The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in various place, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 25 Apr 2022
    5.4
    Medium

    CVE-2022-1152

    Last Modified: 21 Nov 2024

    The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in the response via the menubar AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-1094

    Last Modified: 5 May 2025

    The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2022-1092

    Last Modified: 17 Oct 2025

    The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-1027

    Last Modified: 21 Nov 2024

    The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2022-0953

    Last Modified: 21 Nov 2024

    The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

    Published: 25 Apr 2022
    4.8
    Medium

    CVE-2022-0876

    Last Modified: 21 Nov 2024

    The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-0782

    Last Modified: 21 Nov 2024

    The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-0769

    Last Modified: 21 Nov 2024

    The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-0693

    Last Modified: 21 Nov 2024

    The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-0657

    Last Modified: 21 Nov 2024

    The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

    Published: 25 Apr 2022
    7.5
    High

    CVE-2022-0656

    Last Modified: 21 Nov 2024

    The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2022-0634

    Last Modified: 21 Nov 2024

    The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-0541

    Last Modified: 21 Nov 2024

    The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

    Published: 25 Apr 2022
    5.4
    Medium

    CVE-2022-0398

    Last Modified: 21 Nov 2024

    The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2022-0363

    Last Modified: 17 Oct 2025

    The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2022-0287

    Last Modified: 17 Oct 2025

    The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

    Published: 25 Apr 2022
    8.8
    High

    CVE-2021-4225

    Last Modified: 21 Nov 2024

    The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2021-46782

    Last Modified: 21 Nov 2024

    The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2021-46781

    Last Modified: 21 Nov 2024

    The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2021-46780

    Last Modified: 21 Nov 2024

    The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2021-25111

    Last Modified: 21 Nov 2024

    The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue

    Published: 25 Apr 2022
    8.1
    High

    CVE-2021-25094

    Last Modified: 21 Apr 2025

    The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

    Published: 25 Apr 2022
    8.8
    High

    CVE-2021-24957

    Last Modified: 21 Nov 2024

    The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2021-24805

    Last Modified: 21 Nov 2024

    The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status.

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2021-24800

    Last Modified: 21 Nov 2024

    The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.

    Published: 25 Apr 2022
    6.5
    Medium

    CVE-2022-27374

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.

    Published: 25 Apr 2022
    6.5
    Medium

    CVE-2022-27375

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2022-26596

    Last Modified: 5 Jul 2026

    Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.

    Published: 25 Apr 2022
    7.8
    High

    CVE-2022-22392

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.

    Published: 25 Apr 2022
    8
    High

    CVE-2021-39040

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.

    Published: 25 Apr 2022