Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0515 1 Craterapp 1 Crater 2022-03-28 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
CVE-2022-26555 1 Eova 1 Eova 2022-03-28 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.
CVE-2022-26247 1 Teamwork Management System Project 1 Teamwork Management System 2022-03-28 4.3 MEDIUM 5.9 MEDIUM
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.
CVE-2022-0681 1 Simple-membership-plugin 1 Simple Membership 2022-03-28 4.3 MEDIUM 6.5 MEDIUM
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
CVE-2022-26246 1 Tms Project 1 Tms 2022-03-28 4.3 MEDIUM 6.1 MEDIUM
TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate.
CVE-2022-0640 1 Wpdevart 1 Pricing Table Builder 2022-03-28 4.3 MEDIUM 6.1 MEDIUM
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-25464 1 Html-js 1 Doracms 2022-03-28 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-24125 1 Fromsoftware 1 Dark Souls Iii 2022-03-28 6.5 MEDIUM 8.8 HIGH
The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is only restricted on the client side, and can thus be bypassed with a modified client.
CVE-2022-0628 1 Accesspressthemes 1 Ap Mega Menu 2022-03-28 4.3 MEDIUM 6.1 MEDIUM
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0627 1 Tms-outsource 1 Amelia 2022-03-28 4.3 MEDIUM 6.1 MEDIUM
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
CVE-2022-0616 1 Tms-outsource 1 Amelia 2022-03-28 4.3 MEDIUM 4.3 MEDIUM
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack
CVE-2022-0591 1 Subtlewebinc 1 Formcraft3 2022-03-28 6.4 MEDIUM 9.1 CRITICAL
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
CVE-2022-0991 1 Admidio 1 Admidio 2022-03-28 6.4 MEDIUM 7.1 HIGH
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.
CVE-2022-0423 1 3dflipbook 1 3d Flipbook 2022-03-28 3.5 LOW 5.4 MEDIUM
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.
CVE-2022-0590 1 Ait-pro 1 Bulletproof Security 2022-03-28 3.5 LOW 4.8 MEDIUM
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-0364 1 Webnus 1 Modern Events Calendar Lite 2022-03-28 3.5 LOW 5.4 MEDIUM
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
CVE-2022-0229 1 Miniorange 1 Google Authenticator 2022-03-28 5.8 MEDIUM 8.1 HIGH
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
CVE-2022-0694 1 Elbtide 1 Advanced Booking Calendar 2022-03-28 7.5 HIGH 9.8 CRITICAL
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CVE-2021-25019 1 Squirrly 1 Seo 2022-03-28 4.3 MEDIUM 6.1 MEDIUM
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-26267 1 Piwigo 1 Piwigo 2022-03-28 5.0 MEDIUM 7.5 HIGH
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.