CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2022-1166

    Last Modified: 21 Nov 2024

    The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen.

    Published: 4 Apr 2022
    9.1
    Critical

    CVE-2022-1165

    Last Modified: 21 Nov 2024

    The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-1164

    Last Modified: 21 Nov 2024

    The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature

    Published: 4 Apr 2022
    4.8
    Medium

    CVE-2022-0958

    Last Modified: 21 Nov 2024

    The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-0901

    Last Modified: 21 Nov 2024

    The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

    Published: 4 Apr 2022
    7.2
    High

    CVE-2022-0887

    Last Modified: 21 Nov 2024

    The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

    Published: 4 Apr 2022
    4.8
    Medium

    CVE-2022-0884

    Last Modified: 21 Nov 2024

    The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-0864

    Last Modified: 21 Nov 2024

    The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2022-0837

    Last Modified: 21 Nov 2024

    The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment history. A malicious actor can abuse this vulnerability to drain out the account balance by keep sending SMS notification.

    Published: 4 Apr 2022
    6.5
    Medium

    CVE-2022-0830

    Last Modified: 21 Nov 2024

    The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2022-0825

    Last Modified: 21 Nov 2024

    The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2022-0709

    Last Modified: 21 Nov 2024

    The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

    Published: 4 Apr 2022
    7.2
    High

    CVE-2022-0537

    Last Modified: 21 Nov 2024

    The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is added. No validation is performed on the content of the file, triggering an RCE vulnerability by uploading a web shell. Further the name parameter is not sanitized, allowing the payload to be uploaded to any directory to which the server has write access.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-0431

    Last Modified: 21 Nov 2024

    The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

    Published: 4 Apr 2022
    6.5
    Medium

    CVE-2022-0404

    Last Modified: 21 Nov 2024

    The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site.

    Published: 4 Apr 2022
    8.1
    High

    CVE-2022-0403

    Last Modified: 21 Nov 2024

    The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders.

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2021-25113

    Last Modified: 21 Nov 2024

    The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2021-25048

    Last Modified: 21 Nov 2024

    The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2021-43461

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43460

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2021-43459

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43458

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43457

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43456

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43455

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.

    Published: 4 Apr 2022
    8.6
    High

    CVE-2022-1026

    Last Modified: 21 Nov 2024

    Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

    Published: 4 Apr 2022
    7.8
    High

    CVE-2021-43454

    Last Modified: 21 Nov 2024

    An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

    Published: 4 Apr 2022
    4.9
    Medium

    CVE-2022-28063

    Last Modified: 21 Nov 2024

    Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.

    Published: 4 Apr 2022
    8.8
    High

    CVE-2022-28062

    Last Modified: 21 Nov 2024

    Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.

    Published: 4 Apr 2022
    8.8
    High

    CVE-2022-27435

    Last Modified: 21 Nov 2024

    An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

    Published: 4 Apr 2022
    4.8
    Medium

    CVE-2022-27436

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.

    Published: 4 Apr 2022
    6.1
    Medium

    CVE-2022-26616

    Last Modified: 21 Nov 2024

    PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2021-44138

    Last Modified: 21 Nov 2024

    There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

    Published: 4 Apr 2022
    5.4
    Medium

    CVE-2021-33616

    Last Modified: 21 Nov 2024

    RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.

    Published: 4 Apr 2022
    6.5
    Medium

    CVE-2022-1225

    Last Modified: 21 Nov 2024

    Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

    Published: 4 Apr 2022
    6.5
    Medium

    CVE-2022-1223

    Last Modified: 24 Feb 2026

    Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

    Published: 4 Apr 2022
    6.5
    Medium

    CVE-2022-1224

    Last Modified: 21 Nov 2024

    Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

    Published: 4 Apr 2022
    5.5
    Medium

    CVE-2022-24191

    Last Modified: 21 Nov 2024

    In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

    Published: 4 Apr 2022
    9.9
    Critical

    CVE-2022-0939

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

    Published: 4 Apr 2022
    5.5
    Medium

    CVE-2022-3061

    Last Modified: 21 Nov 2024

    Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't check the value of 'pixclock', so it may cause a divide by zero error.

    Published: 4 Apr 2022
    8.1
    High

    CVE-2022-24801

    Last Modified: 23 Apr 2025

    Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have been addressed, such as by upgrading them; or filter malformed requests by other means, such as configuration of an upstream proxy.

    Published: 4 Apr 2022
    5.5
    Medium

    CVE-2022-1222

    Last Modified: 21 Nov 2024

    Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.

    Published: 4 Apr 2022
    7.5
    High

    CVE-2022-24785

    Last Modified: 3 Nov 2025

    Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

    Published: 4 Apr 2022
    8.8
    High

    CVE-2022-27249

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.

    Published: 3 Apr 2022
    6.5
    Medium

    CVE-2022-27248

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint. An attack uses the path field to CaddemServiceJS/CaddemService.svc/rest/DownloadDwg.

    Published: 3 Apr 2022
    9.1
    Critical

    CVE-2022-26530

    Last Modified: 21 Nov 2024

    swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor.

    Published: 3 Apr 2022
    7.5
    High

    CVE-2022-26233

    Last Modified: 21 Nov 2024

    Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

    Published: 3 Apr 2022
    6.8
    Medium

    CVE-2021-30066

    Last Modified: 21 Nov 2024

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

    Published: 3 Apr 2022
    7.5
    High

    CVE-2021-30065

    Last Modified: 21 Nov 2024

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

    Published: 3 Apr 2022
    9.8
    Critical

    CVE-2021-30064

    Last Modified: 21 Nov 2024

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

    Published: 3 Apr 2022