Search
Total
46623 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-29055 | 1 School File Management System Project | 1 School File Management System | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php. | |||||
| CVE-2021-46824 | 1 School File Management System Project | 1 School File Management System | 2022-06-29 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php. | |||||
| CVE-2022-34178 | 1 Jenkins | 1 Embeddable Build Status | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||||
| CVE-2022-20651 | 1 Cisco | 1 Adaptive Security Device Manager | 2022-06-29 | 2.1 LOW | 5.5 MEDIUM |
| A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view the credentials of other users of the shared device. | |||||
| CVE-2022-23078 | 1 Habitica | 1 Habitica | 2022-06-29 | 5.8 MEDIUM | 6.1 MEDIUM |
| In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page. | |||||
| CVE-2021-41432 | 1 Flatpress | 1 Flatpress | 2022-06-29 | 3.5 LOW | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content. | |||||
| CVE-2022-34013 | 1 Zhyd | 1 Oneblog | 2022-06-29 | 4.0 MEDIUM | 4.3 MEDIUM |
| OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module. | |||||
| CVE-2022-34012 | 1 Zhyd | 1 Oneblog | 2022-06-29 | 4.0 MEDIUM | 6.5 MEDIUM |
| Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges. | |||||
| CVE-2022-34011 | 1 Zhyd | 1 Oneblog | 2022-06-29 | 4.0 MEDIUM | 4.3 MEDIUM |
| OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls. | |||||
| CVE-2022-23077 | 1 Habitica | 1 Habitica | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page. | |||||
| CVE-2022-33113 | 1 Jflyfox | 1 Jfinal Cms | 2022-06-29 | 3.5 LOW | 5.4 MEDIUM |
| Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module. | |||||
| CVE-2022-31095 | 1 Discourse | 1 Discourse-chat | 2022-06-29 | 4.0 MEDIUM | 6.5 MEDIUM |
| discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup endpoint, primarily affecting direct message channels. There are no known workarounds for this issue, and users are advised to update the plugin. | |||||
| CVE-2022-1596 | 1 Abb | 6 Rex640 Pcl1, Rex640 Pcl1 Firmware, Rex640 Pcl2 and 3 more | 2022-06-29 | 4.0 MEDIUM | 6.5 MEDIUM |
| Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node. | |||||
| CVE-2022-23342 | 1 Hyland | 1 Onbase | 2022-06-29 | 5.0 MEDIUM | 5.3 MEDIUM |
| The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems. | |||||
| CVE-2022-30874 | 1 Nukeviet | 1 Nukeviet | 2022-06-29 | 3.5 LOW | 5.4 MEDIUM |
| There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02. | |||||
| CVE-2022-33119 | 1 Nuuo | 2 Nvrsolo, Nvrsolo Firmware | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php. | |||||
| CVE-2022-32125 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job. | |||||
| CVE-2022-32124 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/. | |||||
| CVE-2022-32128 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im. | |||||
| CVE-2022-32127 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total. | |||||
| CVE-2022-32126 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company. | |||||
| CVE-2022-32131 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show. | |||||
| CVE-2022-32130 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_resume/total/nature. | |||||
| CVE-2022-32129 | 1 74cms | 1 74cmsse | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/safety/trade. | |||||
| CVE-2022-31373 | 1 Contec | 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware | 2022-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php. | |||||
| CVE-2022-31306 | 1 F5 | 1 Njs | 2022-06-29 | 4.3 MEDIUM | 5.5 MEDIUM |
| Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c. | |||||
| CVE-2022-31303 | 1 Maccms | 1 Maccms | 2022-06-29 | 3.5 LOW | 5.4 MEDIUM |
| maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | |||||
| CVE-2022-2174 | 1 Microweber | 1 Microweber | 2022-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18. | |||||
| CVE-2022-23081 | 1 Openlibrary | 1 Openlibrary | 2022-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS. | |||||
| CVE-2022-32159 | 1 Infogami | 1 Infogami | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS. | |||||
| CVE-2022-1610 | 1 Seamless Donations Project | 1 Seamless Donations | 2022-06-28 | 4.3 MEDIUM | 6.5 MEDIUM |
| The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
| CVE-2022-31786 | 1 Ideaco | 1 Idealms | 2022-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO. | |||||
| CVE-2022-32974 | 1 Tenable | 1 Nessus | 2022-06-28 | 4.0 MEDIUM | 6.5 MEDIUM |
| An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials. | |||||
| CVE-2022-25585 | 1 Unioncms Project | 1 Unioncms | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings. | |||||
| CVE-2022-31478 | 1 Sr.solutions | 1 Usertakeover | 2022-06-28 | 4.0 MEDIUM | 4.3 MEDIUM |
| The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function. | |||||
| CVE-2021-36761 | 1 Qlik | 1 Qlik Sense | 2022-06-28 | 5.0 MEDIUM | 5.3 MEDIUM |
| The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF. | |||||
| CVE-2021-39006 | 2 Ibm, Linux | 2 Qradar Wincollect, Linux Kernel | 2022-06-28 | 5.0 MEDIUM | 5.3 MEDIUM |
| IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549. | |||||
| CVE-2022-31302 | 1 Maccms | 1 Maccms | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | |||||
| CVE-2022-31062 | 1 Glpi-project | 1 Glpi Inventory | 2022-06-28 | 5.0 MEDIUM | 5.3 MEDIUM |
| ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used. | |||||
| CVE-2022-23072 | 1 Tandoor | 1 Recipes | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover. | |||||
| CVE-2017-20065 | 1 Supsystic | 1 Popup | 2022-06-28 | 4.3 MEDIUM | 4.3 MEDIUM |
| A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2022-1945 | 1 Colorlib | 1 Coming Soon \& Maintenance Mode | 2022-06-28 | 3.5 LOW | 4.8 MEDIUM |
| The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup) | |||||
| CVE-2022-1818 | 1 Multi-page Toolkit Project | 1 Multi-page Toolkit | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well | |||||
| CVE-2022-1717 | 1 Wp-experts | 1 Custom Share Buttons With Floating Sidebar | 2022-06-28 | 3.5 LOW | 4.8 MEDIUM |
| The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |||||
| CVE-2022-1915 | 1 Wpreviewslider | 1 Wp Zillow Review Slider | 2022-06-28 | 3.5 LOW | 4.8 MEDIUM |
| The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite) | |||||
| CVE-2021-41924 | 1 Webkul | 1 Krayin | 2022-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2022-1826 | 1 Cross-linker Project | 1 Cross-linker | 2022-06-28 | 4.3 MEDIUM | 6.5 MEDIUM |
| The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |||||
| CVE-2022-23074 | 1 Tandoor | 1 Recipes | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover. | |||||
| CVE-2022-23073 | 1 Tandoor | 1 Recipes | 2022-06-28 | 3.5 LOW | 5.4 MEDIUM |
| In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover. | |||||
| CVE-2022-1630 | 1 Wp-email Project | 1 Wp-email | 2022-06-28 | 4.3 MEDIUM | 6.5 MEDIUM |
| The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack | |||||
