Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21828 1 Ivanti 1 Incapptic Connect 2022-03-21 6.5 MEDIUM 7.2 HIGH
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.
CVE-2022-22735 1 Sedlex 1 Simple Quotation 2022-03-21 6.5 MEDIUM 8.8 HIGH
The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacks
CVE-2022-24097 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2022-03-21 9.3 HIGH 7.8 HIGH
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-22734 1 Sedlex 1 Simple Quotation 2022-03-21 4.3 MEDIUM 6.1 MEDIUM
The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could make a logged in admin create or edit arbitrary quote, and put Cross-Site Scripting payloads in them
CVE-2022-0960 1 Showdoc 1 Showdoc 2022-03-21 3.5 LOW 5.4 MEDIUM
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0703 1 Gd-mylist Project 1 Gd-mylist 2022-03-21 3.5 LOW 4.8 MEDIUM
The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0702 1 Unboxinteractive 1 Petfinder-listings 2022-03-21 3.5 LOW 4.8 MEDIUM
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0701 1 Seo-301-meta Project 1 Seo-301-meta 2022-03-21 3.5 LOW 4.8 MEDIUM
The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0700 1 Chrsinteractive 1 Simple Tracking 2022-03-21 3.5 LOW 4.8 MEDIUM
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0684 1 Wp Home Page Menu Project 1 Wp Home Page Menu 2022-03-21 3.5 LOW 4.8 MEDIUM
The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0674 1 Kunze-medien 1 Kunze Law 2022-03-21 3.5 LOW 4.8 MEDIUM
The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-0659 1 Sync Qcloud Cos Project 1 Sync Qcloud Cos 2022-03-21 3.5 LOW 4.8 MEDIUM
The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-24096 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2022-03-21 9.3 HIGH 7.8 HIGH
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-24095 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2022-03-21 9.3 HIGH 7.8 HIGH
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-24094 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2022-03-21 9.3 HIGH 7.8 HIGH
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-24090 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2022-03-21 4.3 MEDIUM 5.5 MEDIUM
Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-0906 1 Microweber 1 Microweber 2022-03-21 3.5 LOW 4.8 MEDIUM
Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.
CVE-2022-0905 1 Gitea 1 Gitea 2022-03-21 5.5 MEDIUM 7.1 HIGH
Improper Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
CVE-2022-0230 1 Bwp-google-xml-sitemaps Project 1 Bwp-google-xml-sitemaps 2022-03-20 4.3 MEDIUM 6.1 MEDIUM
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
CVE-2022-0169 1 10web 1 Photo Gallery 2022-03-20 7.5 HIGH 9.8 CRITICAL
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection