Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-37977 | 3 Debian, Fedoraproject, Google | 3 Debian Linux, Fedora, Chrome | 2022-02-18 | 6.8 MEDIUM | 8.8 HIGH |
Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |||||
CVE-2021-37984 | 2 Debian, Google | 2 Debian Linux, Chrome | 2022-02-18 | 6.8 MEDIUM | 8.8 HIGH |
Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |||||
CVE-2022-0201 | 2 Permalink Manager Lite Project, Permalink Manager Project | 2 Permalink Manager Lite, Permalink Manager | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2022-23384 | 1 Yzmcms | 1 Yzmcms | 2022-02-18 | 6.8 MEDIUM | 8.8 HIGH |
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add | |||||
CVE-2022-0176 | 1 Wpbeaveraddons | 1 Powerpack Lite For Beaver Builder | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-0212 | 1 10web | 1 Spidercalendar | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue. | |||||
CVE-2022-0200 | 1 Themify | 1 Portfolio Post | 2022-02-18 | 3.5 LOW | 5.4 MEDIUM |
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-24206 | 1 Tongda2000 | 1 Tongda Oa | 2022-02-18 | 7.5 HIGH | 9.8 CRITICAL |
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter. | |||||
CVE-2022-23902 | 1 Tongda2000 | 1 Tongda Oa | 2022-02-18 | 7.5 HIGH | 9.8 CRITICAL |
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter. | |||||
CVE-2022-23992 | 1 Broadcom | 1 Xcom Data Transport | 2022-02-18 | 10.0 HIGH | 9.8 CRITICAL |
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges. | |||||
CVE-2022-24705 | 1 Accel-ppp | 1 Accel-ppp | 2022-02-18 | 7.5 HIGH | 9.8 CRITICAL |
The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory. If the server connects with a malicious client, crafted client requests can remotely trigger this vulnerability. | |||||
CVE-2022-24704 | 1 Accel-ppp | 1 Accel-ppp | 2022-02-18 | 7.5 HIGH | 9.8 CRITICAL |
The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a fixed buffer &attr->val.integer without any bound checks. If the client connects to the server and sends a large radius packet, a buffer overflow vulnerability will be triggered. | |||||
CVE-2021-46557 | 1 Vicidial | 1 Vicidial | 2022-02-18 | 3.5 LOW | 5.4 MEDIUM |
Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs. | |||||
CVE-2021-46458 | 1 Victor Cms Project | 1 Victor Cms | 2022-02-18 | 5.0 MEDIUM | 7.5 HIGH |
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter. | |||||
CVE-2021-38014 | 3 Debian, Fedoraproject, Google | 3 Debian Linux, Fedora, Chrome | 2022-02-18 | 6.8 MEDIUM | 8.8 HIGH |
Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |||||
CVE-2010-1171 | 1 Redhat | 1 Satellite | 2022-02-18 | 5.5 MEDIUM | N/A |
Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels. | |||||
CVE-2007-2161 | 1 Microsoft | 1 Internet Explorer | 2022-02-18 | 4.3 MEDIUM | N/A |
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/. | |||||
CVE-2022-0633 | 1 Updraftplus | 1 Updraftplus | 2022-02-18 | 4.0 MEDIUM | 6.5 MEDIUM |
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. | |||||
CVE-2021-38003 | 3 Debian, Fedoraproject, Google | 3 Debian Linux, Fedora, Chrome | 2022-02-18 | 6.8 MEDIUM | 8.8 HIGH |
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |||||
CVE-2022-24003 | 1 Samsung | 1 Bixby Vision | 2022-02-18 | 5.0 MEDIUM | 5.3 MEDIUM |
Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent. |