CVE Feed

    Dashboard / CVE

    4.1
    Medium

    CVE-2021-36851

    Last Modified: 20 Feb 2025

    Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color.

    Published: 4 Apr 2022
    3.4
    Low

    CVE-2022-25618

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27

    Published: 4 Apr 2022
    4.1
    Medium

    CVE-2022-25613

    Last Modified: 28 Apr 2026

    Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

    Published: 4 Apr 2022
    8.7
    High

    CVE-2022-1175

    Last Modified: 21 Nov 2024

    Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

    Published: 4 Apr 2022
    8.7
    High

    CVE-2022-1190

    Last Modified: 21 Nov 2024

    Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

    Published: 4 Apr 2022
    9.1
    Critical

    CVE-2022-1162

    Last Modified: 21 Nov 2024

    A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

    Published: 4 Apr 2022
    5.3
    Medium

    CVE-2022-1148

    Last Modified: 21 Nov 2024

    Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

    Published: 4 Apr 2022
    5.3
    Medium

    CVE-2022-1121

    Last Modified: 21 Nov 2024

    A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.

    Published: 4 Apr 2022
    2.4
    Low

    CVE-2022-1111

    Last Modified: 21 Nov 2024

    A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

    Published: 4 Apr 2022
    6.5
    Medium

    CVE-2022-1185

    Last Modified: 21 Nov 2024

    A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file

    Published: 4 Apr 2022
    4.8
    Medium

    CVE-2022-1120

    Last Modified: 21 Nov 2024

    Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration.

    Published: 4 Apr 2022
    4.3
    Medium

    CVE-2022-1174

    Last Modified: 21 Nov 2024

    A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

    Published: 4 Apr 2022
    3.7
    Low

    CVE-2022-1188

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.

    Published: 4 Apr 2022
    4.3
    Medium

    CVE-2022-1105

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled

    Published: 4 Apr 2022
    4.3
    Medium

    CVE-2022-1099

    Last Modified: 21 Nov 2024

    Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab

    Published: 4 Apr 2022
    4.3
    Medium

    CVE-2022-1100

    Last Modified: 21 Nov 2024

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

    Published: 4 Apr 2022
    3.1
    Low

    CVE-2022-1189

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project.

    Published: 4 Apr 2022
    3.1
    Low

    CVE-2022-0740

    Last Modified: 21 Nov 2024

    Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2021-32994

    Last Modified: 16 Apr 2025

    Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2021-32982

    Last Modified: 16 Apr 2025

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.

    Published: 4 Apr 2022
    9.8
    Critical

    CVE-2021-32986

    Last Modified: 16 Apr 2025

    After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.

    Published: 4 Apr 2022
    9.8
    Critical

    CVE-2021-32984

    Last Modified: 16 Apr 2025

    All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2021-32978

    Last Modified: 16 Apr 2025

    The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.

    Published: 4 Apr 2022
    9.8
    Critical

    CVE-2021-32980

    Last Modified: 16 Apr 2025

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is already active.

    Published: 4 Apr 2022
    8.8
    High

    CVE-2021-33008

    Last Modified: 16 Apr 2025

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.

    Published: 4 Apr 2022
    7.2
    High

    CVE-2021-32981

    Last Modified: 16 Apr 2025

    AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    Published: 4 Apr 2022
    7.2
    High

    CVE-2021-32985

    Last Modified: 16 Apr 2025

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2021-33010

    Last Modified: 16 Apr 2025

    An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.

    Published: 4 Apr 2022
    7.2
    High

    CVE-2021-32977

    Last Modified: 16 Apr 2025

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

    Published: 4 Apr 2022
    5.5
    Medium

    CVE-2022-23700

    Last Modified: 21 Nov 2024

    A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2022-23699

    Last Modified: 21 Nov 2024

    A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2022-23698

    Last Modified: 21 Nov 2024

    A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-23697

    Last Modified: 21 Nov 2024

    A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 4 Apr 2022
    6
    Medium

    CVE-2022-27609

    Last Modified: 21 Nov 2024

    Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by users with Administrator privileges. This could result in a user disabling Forcepoint One Endpoint and the protection offered by it.

    Published: 4 Apr 2022
    6
    Medium

    CVE-2022-27608

    Last Modified: 21 Nov 2024

    Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator privileges. This could result in a user disabling anti-tampering mechanisms which would then allow the user to disable Forcepoint One Endpoint and the protection offered by it.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-1233

    Last Modified: 21 Nov 2024

    URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2022-26572

    Last Modified: 21 Nov 2024

    Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.

    Published: 4 Apr 2022
    9.1
    Critical

    CVE-2022-0990

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

    Published: 4 Apr 2022
    8.8
    High

    CVE-2022-24814

    Last Modified: 23 Apr 2025

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to a file uploaded HTML file that loads another uploaded JS file in its script tag. This satisfies the regular content security policy header, which in turn allows the file to run any arbitrary JS. This issue was resolved in version 9.7.0. As a workaround, disable the live embed in the what-you-see-is-what-you-get by adding `{ "media_live_embeds": false }` to the _Options Overrides_ option of the Rich Text HTML interface.

    Published: 4 Apr 2022
    5.3
    Medium

    CVE-2022-24813

    Last Modified: 23 Apr 2025

    CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the `master` branch of CreateWiki's GitHub repository.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2022-24787

    Last Modified: 23 Apr 2025

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Even without dirty nonzero bytes, two bytestrings can compare to equal if one ends with `"\x00"` because there is no comparison of the length. A patch is available and expected to be part of the 0.3.2 release. There are currently no known workarounds.

    Published: 4 Apr 2022
    8.8
    High

    CVE-2021-43464

    Last Modified: 21 Nov 2024

    A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().

    Published: 4 Apr 2022
    9.8
    Critical

    CVE-2022-25569

    Last Modified: 21 Nov 2024

    Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.

    Published: 4 Apr 2022
    7.2
    High

    CVE-2020-28062

    Last Modified: 21 Nov 2024

    An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43463

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2021-43462

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-1170

    Last Modified: 21 Nov 2024

    In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-1169

    Last Modified: 21 Nov 2024

    There is a XSS vulnerability in Careerfy.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-1168

    Last Modified: 21 Nov 2024

    There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-1167

    Last Modified: 21 Nov 2024

    There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.

    Published: 4 Apr 2022