CVE Feed

    Dashboard / CVE

    2.8
    Low

    CVE-2017-20015

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in WEKA INTEREST Security Scanner up to 1.8. This affects an unknown part of the component LAN Viewer. The manipulation with an unknown input leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    2.8
    Low

    CVE-2017-20014

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in WEKA INTEREST Security Scanner up to 1.8. Affected by this issue is some unknown functionality of the component Webspider. The manipulation with an unknown input leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    2.8
    Low

    CVE-2017-20013

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in WEKA INTEREST Security Scanner up to 1.8. Affected by this vulnerability is the Stresstest Configuration Handler. A manipulation leads to a local denial of service. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    2.8
    Low

    CVE-2017-20012

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in WEKA INTEREST Security Scanner up to 1.8. Affected is Stresstest Scheme Handler which leads to a denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    2.8
    Low

    CVE-2017-20011

    Last Modified: 15 Apr 2025

    A vulnerability was found in WEKA INTEREST Security Scanner 1.8. It has been rated as problematic. This issue affects some unknown processing of the component HTTP Handler. The manipulation with an unknown input leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2010-10001

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Shemes GrabIt up to 1.7.2 Beta 4. This affects the component NZB Date Parser. The manipulation of the argument date with the input 1000000000000000 as part of a NZB File leads to a denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Mar 2022
    5.5
    Medium

    CVE-2008-10001

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    5.4
    Medium

    CVE-2005-10001

    Last Modified: 15 Apr 2025

    A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    5
    Medium

    CVE-2003-5003

    Last Modified: 20 Nov 2024

    A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipulation with an unknown input leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    3.7
    Low

    CVE-2003-5002

    Last Modified: 20 Nov 2024

    A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update Handler which allows cleartext transmission of data. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2003-5001

    Last Modified: 20 Nov 2024

    A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/OPTIONS Request leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2021-4191

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

    Published: 28 Mar 2022
    4.7
    Medium

    CVE-2022-0283

    Last Modified: 21 Nov 2024

    An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

    Published: 28 Mar 2022
    5.4
    Medium

    CVE-2022-0136

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

    Published: 28 Mar 2022
    4.3
    Medium

    CVE-2021-39876

    Last Modified: 21 Nov 2024

    In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

    Published: 28 Mar 2022
    3.5
    Low

    CVE-2022-0488

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

    Published: 28 Mar 2022
    3.1
    Low

    CVE-2022-0249

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.

    Published: 28 Mar 2022
    3.1
    Low

    CVE-2022-0344

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project

    Published: 28 Mar 2022
    5.9
    Medium

    CVE-2022-0123

    Last Modified: 21 Nov 2024

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services.

    Published: 28 Mar 2022
    7.7
    High

    CVE-2022-0427

    Last Modified: 21 Nov 2024

    Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

    Published: 28 Mar 2022
    4.2
    Medium

    CVE-2022-0738

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions.

    Published: 28 Mar 2022
    6.5
    Medium

    CVE-2022-0751

    Last Modified: 21 Nov 2024

    Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands

    Published: 28 Mar 2022
    4.3
    Medium

    CVE-2022-0371

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private.

    Published: 28 Mar 2022
    6.5
    Medium

    CVE-2022-0549

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI.

    Published: 28 Mar 2022
    10
    Critical

    CVE-2022-0735

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

    Published: 28 Mar 2022
    7.5
    High

    CVE-2022-27658

    Last Modified: 21 Nov 2024

    Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

    Published: 28 Mar 2022
    3.3
    Low

    CVE-2018-25030

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has been disclosed to the public and may be used.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-26980

    Last Modified: 21 Nov 2024

    Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2015-10002

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Kiddoware Kids Place. This affects the Home Button Protection. A repeated pressing of the button causes a local denial of service. It is recommended to upgrade the affected component.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-0846

    Last Modified: 21 Nov 2024

    The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

    Published: 28 Mar 2022
    4.3
    Medium

    CVE-2022-0833

    Last Modified: 21 Nov 2024

    The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0818

    Last Modified: 21 Nov 2024

    The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-0787

    Last Modified: 21 Nov 2024

    The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-0784

    Last Modified: 21 Nov 2024

    The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

    Published: 28 Mar 2022
    8.8
    High

    CVE-2022-0770

    Last Modified: 21 Nov 2024

    The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

    Published: 28 Mar 2022
    5.4
    Medium

    CVE-2022-0720

    Last Modified: 21 Nov 2024

    The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0680

    Last Modified: 21 Nov 2024

    The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configuration_tracker_enable option, which is then displayed in the admin panel without sanitisation and escaping, leading to a Stored Cross-Site Scripting issue

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-0679

    Last Modified: 21 Nov 2024

    The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0647

    Last Modified: 21 Nov 2024

    The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0643

    Last Modified: 21 Nov 2024

    The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0641

    Last Modified: 21 Nov 2024

    The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0621

    Last Modified: 21 Nov 2024

    The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0620

    Last Modified: 21 Nov 2024

    The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0619

    Last Modified: 21 Nov 2024

    The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0600

    Last Modified: 21 Nov 2024

    The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2022-0599

    Last Modified: 21 Nov 2024

    The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

    Published: 28 Mar 2022
    5.4
    Medium

    CVE-2022-0595

    Last Modified: 21 Nov 2024

    The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

    Published: 28 Mar 2022
    8.8
    High

    CVE-2022-0499

    Last Modified: 21 Nov 2024

    The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

    Published: 28 Mar 2022
    4.9
    Medium

    CVE-2022-0493

    Last Modified: 21 Nov 2024

    The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-0479

    Last Modified: 21 Nov 2024

    The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

    Published: 28 Mar 2022