Total
1368 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-4169 | 1 Theme And Plugin Translation For Polylang Project | 1 Theme And Plugin Translation For Polylang | 2022-12-01 | N/A | 5.3 MEDIUM |
The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capability checks in the process_polylang_theme_translation_wp_loaded() function. This makes it possible for unauthenticated attackers to update plugin and theme translation settings and to import translation strings. | |||||
CVE-2022-41930 | 1 Xwiki | 1 Xwiki | 2022-11-30 | N/A | 8.2 HIGH |
org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disabled user to re-enable themselves, or to an attacker to disable any user of the wiki. The problem has been patched in XWiki 13.10.7, 14.5RC1 and 14.4.2. Workarounds: The problem can be patched immediately by editing the page `XWiki.XWikiUserProfileSheet` in the wiki and by performing the changes contained in https://github.com/xwiki/xwiki-platform/commit/5be1cc0adf917bf10899c47723fa451e950271fa. | |||||
CVE-2022-41929 | 1 Xwiki | 1 Xwiki | 2022-11-30 | N/A | 4.9 MEDIUM |
org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1. | |||||
CVE-2022-32966 | 1 Realtek | 2 Rtl8111fp-cg, Rtl8111fp-cg Firmware | 2022-11-29 | N/A | 6.5 MEDIUM |
RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service. | |||||
CVE-2022-41937 | 1 Xwiki | 1 Xwiki | 2022-11-28 | N/A | 8.1 HIGH |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8. As a workaround, setting the right of the page Filter.WebHome and making sure only the main wiki administrators can view the application installed on main wiki or edit the page and apply the changed described in commit fb49b4f. | |||||
CVE-2022-0421 | 1 Fivestarplugins | 1 Five Star Restaurant Reservations | 2022-11-23 | N/A | 6.1 MEDIUM |
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments | |||||
CVE-2022-44584 | 1 Watchtowerhq | 1 Watchtower | 2022-11-21 | N/A | 9.1 CRITICAL |
Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress. | |||||
CVE-2022-41692 | 1 Dwbooster | 1 Appointment Hour Booking | 2022-11-21 | N/A | 8.8 HIGH |
Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. | |||||
CVE-2022-43482 | 1 Codepeople | 1 Appointment Booking Calendar | 2022-11-21 | N/A | 8.8 HIGH |
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. | |||||
CVE-2022-4014 | 1 Feehi | 1 Feehicms | 2022-11-18 | N/A | 4.3 MEDIUM |
A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788. | |||||
CVE-2022-3920 | 1 Hashicorp | 1 Consul | 2022-11-18 | N/A | 7.5 HIGH |
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0. | |||||
CVE-2022-45385 | 1 Jenkins | 1 Cloudbees Docker Hub\/registry Notification | 2022-11-18 | N/A | 7.5 HIGH |
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. | |||||
CVE-2022-45399 | 1 Jenkins | 1 Cluster Statistics | 2022-11-17 | N/A | 4.3 MEDIUM |
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics. | |||||
CVE-2022-45394 | 1 Jenkins | 1 Delete Log | 2022-11-17 | N/A | 4.3 MEDIUM |
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs. | |||||
CVE-2022-45389 | 1 Jenkins | 1 Xp-dev | 2022-11-17 | N/A | 5.3 MEDIUM |
A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository. | |||||
CVE-2022-45390 | 1 Jenkins | 1 Loader.io | 2022-11-17 | N/A | 4.3 MEDIUM |
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
CVE-2022-3538 | 1 Webmaster Tools Verification Project | 1 Webmaster Tools Verification | 2022-11-16 | N/A | 6.5 MEDIUM |
The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins | |||||
CVE-2022-2450 | 1 Resmush.it | 1 Resmush.it Image Optimizer | 2022-11-16 | N/A | 4.3 MEDIUM |
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them. | |||||
CVE-2022-1203 | 1 Content Mask Project | 1 Content Mask | 2022-11-16 | 4.0 MEDIUM | 4.3 MEDIUM |
The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options | |||||
CVE-2022-39879 | 1 Google | 1 Android | 2022-11-10 | N/A | 3.3 LOW |
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid. |