Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-0347 | The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0348 | Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2. | Unknown | N/A | pimcore | |
CVE-2022-0349 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection | Unknown | N/A | Unknown | |
CVE-2022-0350 | Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13. | Unknown | N/A | vanessa219 | |
CVE-2022-0351 | Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0352 | Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. | Unknown | N/A | janeczku | |
CVE-2022-0353 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. | Unknown | N/A | Lenovo | |
CVE-2022-0354 | A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window. | Unknown | N/A | Lenovo | |
CVE-2022-0355 | Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1. | Unknown | N/A | feross | |
CVE-2022-0357 | Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. | Unknown | N/A | Bitdefender | |
CVE-2022-0358 | A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system. | Unknown | N/A | n/a | |
CVE-2022-0359 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0360 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues | Unknown | N/A | Unknown | |
CVE-2022-0361 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0362 | SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. | Unknown | N/A | star7th | |
CVE-2022-0363 | The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts. | Unknown | N/A | Unknown | |
CVE-2022-0364 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | Unknown | N/A | Unknown | |
CVE-2022-0365 | The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user. | Unknown | N/A | Ricon | |
CVE-2022-0366 | An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1. | Unknown | N/A | n/a | |
CVE-2022-0367 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. | Unknown | N/A | n/a | |
CVE-2022-0368 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0369 | Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Restore Workspace feature. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17227. | Unknown | N/A | Triangle MicroWorks | |
CVE-2022-0370 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | Unknown | N/A | livehelperchat | |
CVE-2022-0371 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private. | Unknown | N/A | GitLab | |
CVE-2022-0372 | Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. | Unknown | N/A | crater-invoice | |
CVE-2022-0373 | Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address | Unknown | N/A | GitLab | |
CVE-2022-0374 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | Unknown | N/A | livehelperchat | |
CVE-2022-0375 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | Unknown | N/A | livehelperchat | |
CVE-2022-0376 | The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | Unknown | N/A | Unknown | |
CVE-2022-0377 | Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use this vulnerability in order to rename an arbitrary image file. By doing this, they could destroy the design of the web site. | Unknown | N/A | Unknown | |
CVE-2022-0378 | Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. | Unknown | N/A | microweber | |
CVE-2022-0379 | Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. | Unknown | N/A | microweber | |
CVE-2022-0380 | The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use of $_SERVER['PHP_SELF'] found in the ~/options-fotobook.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 3.2.3. | Unknown | N/A | Fotobook | |
CVE-2022-0381 | The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0. | Unknown | N/A | Embed Swagger | |
CVE-2022-0382 | An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1. | Unknown | N/A | n/a | |
CVE-2022-0383 | The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks | Unknown | N/A | Unknown | |
CVE-2022-0384 | The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog | Unknown | N/A | Unknown | |
CVE-2022-0385 | The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting | Unknown | N/A | Unknown | |
CVE-2022-0386 | A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710. | Unknown | N/A | Sophos | |
CVE-2022-0387 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | Unknown | N/A | livehelperchat | |
CVE-2022-0388 | The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-0389 | The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-0390 | Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard. | Unknown | N/A | GitLab | |
CVE-2022-0391 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14. | Unknown | N/A | n/a | |
CVE-2022-0392 | Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0393 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0394 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | Unknown | N/A | livehelperchat | |
CVE-2022-0395 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | Unknown | N/A | livehelperchat | |
CVE-2022-0396 | BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection. | Unknown | N/A | ISC | |
CVE-2022-0397 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0398 | The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website | Unknown | N/A | Unknown | |
CVE-2022-0399 | The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0400 | An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos. | Unknown | N/A | n/a | |
CVE-2022-0401 | Path Traversal in NPM w-zip prior to 1.0.12. | Unknown | N/A | yuda-lyu | |
CVE-2022-0402 | The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting. The action is also lacking CSRF, making the attack easier to perform against any user. | Unknown | N/A | Unknown | |
CVE-2022-0403 | The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to call it. Furthermore, as the options passed to the elFinder library does not restrict any file type, users with a role as low as subscriber can Create/Upload/Delete Arbitrary files and folders. | Unknown | N/A | Unknown | |
CVE-2022-0404 | The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing any logged in user (with roles as low as Subscriber) to set arbitrary options to true, potentially leading to Denial of Service by breaking the site. | Unknown | N/A | Unknown | |
CVE-2022-0405 | Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. | Unknown | N/A | janeczku | |
CVE-2022-0406 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. | Unknown | N/A | janeczku | |
CVE-2022-0407 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0408 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0409 | Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2. | Unknown | N/A | star7th | |
CVE-2022-0410 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection | Unknown | N/A | Unknown | |
CVE-2022-0411 | The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection | Unknown | N/A | Unknown | |
CVE-2022-0412 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks | Unknown | N/A | TemplateInvaders | |
CVE-2022-0413 | Use After Free in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0414 | Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0. | Unknown | N/A | dolibarr | |
CVE-2022-0415 | Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. | Unknown | N/A | gogs | |
CVE-2022-0417 | Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0418 | The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed | Unknown | N/A | Unknown | |
CVE-2022-0419 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. | Unknown | N/A | radareorg | |
CVE-2022-0420 | The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks | Unknown | N/A | Unknown | |
CVE-2022-0421 | The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments | Unknown | N/A | Unknown | |
CVE-2022-0422 | The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue | Unknown | N/A | Unknown | |
CVE-2022-0423 | The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook. | Unknown | N/A | Unknown | |
CVE-2022-0424 | The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users | Unknown | N/A | Unknown | |
CVE-2022-0425 | A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks. | Unknown | N/A | GitLab | |
CVE-2022-0426 | The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0427 | Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover | Unknown | N/A | GitLab | |
CVE-2022-0428 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0429 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability. | Unknown | N/A | Unknown | |
CVE-2022-0430 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0. | Unknown | N/A | httpie | |
CVE-2022-0431 | The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0432 | Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0. | Unknown | N/A | mastodon | |
CVE-2022-0433 | A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1. | Unknown | N/A | n/a | |
CVE-2022-0434 | The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks | Unknown | N/A | Unknown | |
CVE-2022-0435 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network. | Unknown | N/A | n/a | |
CVE-2022-0436 | Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2. | Unknown | N/A | gruntjs | |
CVE-2022-0437 | Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. | Unknown | N/A | karma-runner | |
CVE-2022-0439 | The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link. | Unknown | N/A | Unknown | |
CVE-2022-0440 | The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true) | Unknown | N/A | Unknown | |
CVE-2022-0441 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | Unknown | N/A | Unknown | |
CVE-2022-0442 | The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar. | Unknown | N/A | Unknown | |
CVE-2022-0443 | Use After Free in GitHub repository vim/vim prior to 8.2. | Unknown | N/A | vim | |
CVE-2022-0444 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key. | Unknown | N/A | Unknown | |
CVE-2022-0445 | The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack | Unknown | N/A | Unknown | |
CVE-2022-0446 | The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-0447 | The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0448 | The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-0449 | The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in some pages such as the user dashboard, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v