Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-21828 | 1 Ivanti | 1 Incapptic Connect | 2022-03-21 | 6.5 MEDIUM | 7.2 HIGH |
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3. | |||||
CVE-2022-22735 | 1 Sedlex | 1 Simple Quotation | 2022-03-21 | 6.5 MEDIUM | 8.8 HIGH |
The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacks | |||||
CVE-2022-24097 | 3 Adobe, Apple, Microsoft | 3 After Effects, Macos, Windows | 2022-03-21 | 9.3 HIGH | 7.8 HIGH |
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-22734 | 1 Sedlex | 1 Simple Quotation | 2022-03-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could make a logged in admin create or edit arbitrary quote, and put Cross-Site Scripting payloads in them | |||||
CVE-2022-0960 | 1 Showdoc | 1 Showdoc | 2022-03-21 | 3.5 LOW | 5.4 MEDIUM |
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. | |||||
CVE-2022-0703 | 1 Gd-mylist Project | 1 Gd-mylist | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0702 | 1 Unboxinteractive | 1 Petfinder-listings | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0701 | 1 Seo-301-meta Project | 1 Seo-301-meta | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0700 | 1 Chrsinteractive | 1 Simple Tracking | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0684 | 1 Wp Home Page Menu Project | 1 Wp Home Page Menu | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0674 | 1 Kunze-medien | 1 Kunze Law | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0659 | 1 Sync Qcloud Cos Project | 1 Sync Qcloud Cos | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-24096 | 3 Adobe, Apple, Microsoft | 3 After Effects, Macos, Windows | 2022-03-21 | 9.3 HIGH | 7.8 HIGH |
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-24095 | 3 Adobe, Apple, Microsoft | 3 After Effects, Macos, Windows | 2022-03-21 | 9.3 HIGH | 7.8 HIGH |
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-24094 | 3 Adobe, Apple, Microsoft | 3 After Effects, Macos, Windows | 2022-03-21 | 9.3 HIGH | 7.8 HIGH |
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-24090 | 3 Adobe, Apple, Microsoft | 3 Photoshop, Macos, Windows | 2022-03-21 | 4.3 MEDIUM | 5.5 MEDIUM |
Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-0906 | 1 Microweber | 1 Microweber | 2022-03-21 | 3.5 LOW | 4.8 MEDIUM |
Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12. | |||||
CVE-2022-0905 | 1 Gitea | 1 Gitea | 2022-03-21 | 5.5 MEDIUM | 7.1 HIGH |
Improper Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. | |||||
CVE-2022-0230 | 1 Bwp-google-xml-sitemaps Project | 1 Bwp-google-xml-sitemaps | 2022-03-20 | 4.3 MEDIUM | 6.1 MEDIUM |
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins | |||||
CVE-2022-0169 | 1 10web | 1 Photo Gallery | 2022-03-20 | 7.5 HIGH | 9.8 CRITICAL |
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection |