Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-0867 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users | Unknown | N/A | Unknown | |
CVE-2022-0868 | Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. | Unknown | N/A | medialize | |
CVE-2022-0869 | Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3. | Unknown | N/A | nitely | |
CVE-2022-0870 | Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5. | Unknown | N/A | gogs | |
CVE-2022-0871 | Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. | Unknown | N/A | gogs | |
CVE-2022-0873 | The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed | Unknown | N/A | Unknown | |
CVE-2022-0874 | The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-0875 | The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks | Unknown | N/A | Unknown | |
CVE-2022-0876 | The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed | Unknown | N/A | Unknown | |
CVE-2022-0877 | Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3. | Unknown | N/A | bookstackapp | |
CVE-2022-0878 | Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of Charge (SoC) with the Electric Vehicle Supply Equipment (EVSE) CCS uses a high-bandwidth IP link provided by the HomePlug Green PHY (HPGP) power-line communication (PLC) technology. The attack interrupts necessary control communication between the vehicle and charger, causing charging sessions to abort. The attack can be conducted wirelessly from a distance using electromagnetic interference, allowing individual vehicles or entire fleets to be disrupted simultaneously. In addition, the attack can be mounted with off-the-shelf radio hardware and minimal technical knowledge. With a power budget of 1 W, the attack is successful from around 47 m distance. The exploited behavior is a required part of the HomePlug Green PHY, DIN 70121 & ISO 15118 standards and all known implementations exhibit it. In addition to electric cars, Brokenwire affects electric ships, airplanes and heavy duty vehicles utilising these standards. | Unknown | N/A | Combined Charging System | |
CVE-2022-0879 | The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0880 | Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. | Unknown | N/A | star7th | |
CVE-2022-0881 | Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. | Unknown | N/A | chocobozzz | |
CVE-2022-0882 | A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater. | Unknown | N/A | Google LLC | |
CVE-2022-0883 | SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | Unknown | N/A | SNOW | |
CVE-2022-0884 | The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed | Unknown | N/A | Unknown | |
CVE-2022-0885 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments. | Unknown | N/A | Unknown | |
CVE-2022-0887 | The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability. | Unknown | N/A | Unknown | |
CVE-2022-0888 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0 | Unknown | N/A | SaturdayDrive | |
CVE-2022-0889 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12. | Unknown | N/A | SaturdayDrive | |
CVE-2022-0890 | NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2. | Unknown | N/A | mruby | |
CVE-2022-0891 | A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact | Unknown | N/A | libtiff | |
CVE-2022-0892 | The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Unknown | N/A | Unknown | |
CVE-2022-0893 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. | Unknown | N/A | pimcore | |
CVE-2022-0894 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. | Unknown | N/A | pimcore | |
CVE-2022-0895 | Static Code Injection in GitHub repository microweber/microweber prior to 1.3. | Unknown | N/A | microweber | |
CVE-2022-0896 | Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3. | Unknown | N/A | microweber | |
CVE-2022-0897 | A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd). | Unknown | N/A | n/a | |
CVE-2022-0898 | The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues | Unknown | N/A | Unknown | |
CVE-2022-0899 | The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting. | Unknown | N/A | Unknown | |
CVE-2022-0900 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NetDataSoft DivvyDrive allows Stored XSS.This issue affects DivvyDrive: from unspecified before v.4.6.2.0. | Unknown | N/A | NetDataSoft | |
CVE-2022-0901 | The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters | Unknown | N/A | Unknown | |
CVE-2022-0902 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node. | Unknown | N/A | ABB | |
CVE-2022-0903 | A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body. | Unknown | N/A | Mattermost | |
CVE-2022-0904 | A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document. | Unknown | N/A | Mattermost | |
CVE-2022-0905 | Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. | Unknown | N/A | go-gitea | |
CVE-2022-0906 | Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12. | Unknown | N/A | microweber | |
CVE-2022-0907 | Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2. | Unknown | N/A | libtiff | |
CVE-2022-0908 | Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file. | Unknown | N/A | TIFF Software Distribution | |
CVE-2022-0909 | Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa. | Unknown | N/A | libtiff | |
CVE-2022-0910 | A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticated attacker to bypass the second authentication phase to connect the IPsec VPN server even though the two-factor authentication (2FA) was enabled. | Unknown | N/A | Zyxel | |
CVE-2022-0911 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. | Unknown | N/A | pimcore | |
CVE-2022-0912 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11. | Unknown | N/A | microweber | |
CVE-2022-0913 | Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3. | Unknown | N/A | microweber | |
CVE-2022-0914 | The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example | Unknown | N/A | Unknown | |
CVE-2022-0915 | There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user. | Unknown | N/A | Logitech | |
CVE-2022-0916 | An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations. | Unknown | N/A | Logitech | |
CVE-2022-0918 | A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing. | Unknown | N/A | n/a | |
CVE-2022-0919 | The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it. | Unknown | N/A | Unknown | |
CVE-2022-0920 | The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data | Unknown | N/A | Unknown | |
CVE-2022-0921 | Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0922 | The software does not perform any authentication for critical system functionality. | Unknown | N/A | Philips | |
CVE-2022-0923 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | Unknown | N/A | Delta Electronics | |
CVE-2022-0924 | Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4. | Unknown | N/A | libtiff | |
CVE-2022-0926 | File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0928 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0929 | XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11. | Unknown | N/A | microweber | |
CVE-2022-0930 | File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0932 | Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2. | Unknown | N/A | saleor | |
CVE-2022-0934 | A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service. | Unknown | N/A | n/a | |
CVE-2022-0935 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. | Unknown | N/A | livehelperchat | |
CVE-2022-0936 | Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. | Unknown | N/A | autolab | |
CVE-2022-0937 | Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0938 | Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0939 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | Unknown | N/A | janeczku | |
CVE-2022-0940 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0941 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0942 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0943 | Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. | Unknown | N/A | vim | |
CVE-2022-0944 | Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1. | Unknown | N/A | sqlpad | |
CVE-2022-0945 | Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0946 | Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0947 | A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration. | Unknown | N/A | ABB | |
CVE-2022-0948 | The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection | Unknown | N/A | Unknown | |
CVE-2022-0949 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection | Unknown | N/A | Unknown | |
CVE-2022-0950 | Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0951 | File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0952 | The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog. | Unknown | N/A | Unknown | |
CVE-2022-0953 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters | Unknown | N/A | Unknown | |
CVE-2022-0954 | Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11. | Unknown | N/A | microweber | |
CVE-2022-0955 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4. | Unknown | N/A | pimcore | |
CVE-2022-0956 | Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0957 | Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0958 | The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | Unknown | N/A | Unknown | |
CVE-2022-0959 | A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write. | Unknown | N/A | n/a | |
CVE-2022-0960 | Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0961 | The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0962 | Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0963 | Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0964 | Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0965 | Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0966 | Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10. | Unknown | N/A | star7th | |
CVE-2022-0967 | Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. | Unknown | N/A | star7th | |
CVE-2022-0968 | The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12. | Unknown | N/A | microweber | |
CVE-2022-0969 | The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-0970 | Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. | Unknown | N/A | getgrav | |
CVE-2022-0971 | Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-0972 | Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-0973 | Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v