Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-29818 | 1 Jetbrains | 1 Intellij Idea | 2022-05-05 | 3.6 LOW | 7.1 HIGH |
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed | |||||
CVE-2021-36460 | 1 Veryfitpro Project | 1 Veryfitpro | 2022-05-05 | 4.6 MEDIUM | 7.8 HIGH |
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless. | |||||
CVE-2022-29821 | 1 Jetbrains | 1 Pycharm | 2022-05-05 | 4.4 MEDIUM | 7.7 HIGH |
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible | |||||
CVE-2022-1396 | 1 Donorbox | 1 Donorbox | 2022-05-05 | 3.5 LOW | 4.8 MEDIUM |
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed | |||||
CVE-2021-45836 | 1 Terra-master | 3 F2-210, F4-210, Tos | 2022-05-05 | 9.0 HIGH | 8.8 HIGH |
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app. | |||||
CVE-2021-24805 | 1 Designwall | 1 Dw Question \& Answer | 2022-05-05 | 4.3 MEDIUM | 4.3 MEDIUM |
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status. | |||||
CVE-2021-24800 | 1 Designwall | 1 Dw Question \& Answer | 2022-05-05 | 4.0 MEDIUM | 4.3 MEDIUM |
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments. | |||||
CVE-2022-28094 | 1 Online Sports Complex Booking System Project | 1 Online Sports Complex Booking System | 2022-05-05 | 4.3 MEDIUM | 6.1 MEDIUM |
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php. | |||||
CVE-2022-28093 | 1 Online Sports Complex Booking System Project | 1 Online Sports Complex Booking System | 2022-05-05 | 7.5 HIGH | 9.8 CRITICAL |
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-28525 | 1 Ed01-cms Project | 1 Ed01-cms | 2022-05-04 | 6.5 MEDIUM | 8.8 HIGH |
ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | |||||
CVE-2022-28524 | 1 Ed01-cms Project | 1 Ed01-cms | 2022-05-04 | 7.5 HIGH | 9.8 CRITICAL |
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | |||||
CVE-2022-28918 | 1 Njtech | 1 Greencms | 2022-05-04 | 5.5 MEDIUM | 8.1 HIGH |
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=. | |||||
CVE-2022-26564 | 1 Digitaldruid | 1 Hoteldruid | 2022-05-04 | 4.3 MEDIUM | 6.1 MEDIUM |
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php. | |||||
CVE-2022-29415 | 1 Ravpage Project | 1 Ravpage | 2022-05-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress. | |||||
CVE-2022-28058 | 1 Verydows | 1 Verydows | 2022-05-04 | 5.5 MEDIUM | 8.1 HIGH |
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php. | |||||
CVE-2022-28448 | 1 Nopcommerce | 1 Nopcommerce | 2022-05-04 | 3.5 LOW | 5.4 MEDIUM |
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info. | |||||
CVE-2022-28059 | 1 Verydows | 1 Verydows | 2022-05-04 | 5.5 MEDIUM | 8.1 HIGH |
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php. | |||||
CVE-2022-1461 | 1 Open-emr | 1 Openemr | 2022-05-04 | 4.0 MEDIUM | 6.5 MEDIUM |
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. | |||||
CVE-2022-28449 | 1 Nopcommerce | 1 Nopcommerce | 2022-05-04 | 4.3 MEDIUM | 6.1 MEDIUM |
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system. | |||||
CVE-2022-1459 | 1 Open-emr | 1 Openemr | 2022-05-04 | 5.5 MEDIUM | 8.3 HIGH |
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. |