Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-25163 | 1 Osisoft | 1 Pi Vision | 2022-04-26 | 4.9 MEDIUM | 7.3 HIGH |
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions. | |||||
CVE-2022-1341 | 1 Bwm-ng Project | 1 Bwm-ng | 2022-04-26 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/options.c. | |||||
CVE-2022-1088 | 1 Contextureintl | 1 Page Security \& Membership | 2022-04-26 | 3.5 LOW | 4.8 MEDIUM |
The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-1063 | 1 Thank Me Later Project | 1 Thank Me Later | 2022-04-26 | 3.5 LOW | 4.8 MEDIUM |
The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputting it in the Messages list, which could allow high privileges users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-1054 | 1 Wpchill | 1 Rsvp And Event Management | 2022-04-26 | 5.0 MEDIUM | 5.3 MEDIUM |
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events | |||||
CVE-2022-1037 | 1 Villatheme | 1 Exmage | 2022-04-26 | 6.5 MEDIUM | 7.2 HIGH |
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs | |||||
CVE-2021-23286 | 1 Eaton | 1 Intelligent Power Manager | 2022-04-26 | 7.9 HIGH | 8.0 HIGH |
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions. | |||||
CVE-2021-23285 | 1 Eaton | 1 Intelligent Power Manager | 2022-04-26 | 3.5 LOW | 4.8 MEDIUM |
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions. | |||||
CVE-2021-23284 | 1 Eaton | 1 Intelligent Power Manager Infrastructure | 2022-04-26 | 3.5 LOW | 4.8 MEDIUM |
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions. | |||||
CVE-2022-23975 | 1 Accesspressthemes | 1 Access Demo Importer | 2022-04-26 | 4.3 MEDIUM | 6.5 MEDIUM |
Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. | |||||
CVE-2022-23976 | 1 Accesspressthemes | 1 Access Demo Importer | 2022-04-26 | 5.8 MEDIUM | 8.1 HIGH |
Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). | |||||
CVE-2022-27652 | 4 Fedoraproject, Kubernetes, Mobyproject and 1 more | 4 Fedora, Cri-o, Moby and 1 more | 2022-04-26 | 4.6 MEDIUM | 5.3 MEDIUM |
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. | |||||
CVE-2022-0661 | 1 Ad Injection Project | 1 Ad Injection | 2022-04-26 | 6.5 MEDIUM | 7.2 HIGH |
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set. | |||||
CVE-2022-0737 | 1 Text Hover Project | 1 Text Hover | 2022-04-26 | 3.5 LOW | 4.8 MEDIUM |
The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-0765 | 1 Loco Translate Project | 1 Loco Translate | 2022-04-26 | 3.5 LOW | 5.4 MEDIUM |
The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability. | |||||
CVE-2022-0780 | 1 Searchiq | 1 Searchiq | 2022-04-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter | |||||
CVE-2022-0879 | 1 Calderaforms | 1 Caldera Forms | 2022-04-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-0785 | 1 Daily Prayer Time Project | 1 Daily Prayer Time | 2022-04-26 | 7.5 HIGH | 9.8 CRITICAL |
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | |||||
CVE-2022-0994 | 1 Incsub | 1 Hummingbird | 2022-04-26 | 3.5 LOW | 4.8 MEDIUM |
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2020-13113 | 4 Canonical, Debian, Libexif Project and 1 more | 4 Ubuntu Linux, Debian Linux, Libexif and 1 more | 2022-04-26 | 6.4 MEDIUM | 8.2 HIGH |
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions. |