Export limit exceeded: 43150 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (43150 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0203 1 Craterapp 1 Crater 2024-11-21 5.3 Medium
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
CVE-2022-0190 1 Acnam 1 Ad Invalid Click Protector 2024-11-21 8.8 High
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.
CVE-2022-0179 1 Snipeitapp 1 Snipe-it 2024-11-21 5.4 Medium
snipe-it is vulnerable to Missing Authorization
CVE-2022-0169 1 10web 1 Photo Gallery 2024-11-21 9.8 Critical
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CVE-2022-0164 1 Wpdevart 1 Coming Soon And Maintenance Mode 2024-11-21 4.3 Medium
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users
CVE-2022-0163 1 Rednao 1 Smart Forms 2024-11-21 6.5 Medium
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.
CVE-2022-0153 1 Fork-cms 1 Fork Cms 2024-11-21 7.5 High
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.
CVE-2022-0152 1 Gitlab 1 Gitlab 2024-11-21 6.5 Medium
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.
CVE-2022-0125 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.
CVE-2022-0117 2 Fedoraproject, Google 2 Fedora, Chrome 2024-11-21 6.5 Medium
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2022-0102 2 Fedoraproject, Google 2 Fedora, Chrome 2024-11-21 8.8 High
Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4313 1 Nethserver-phonenehome Project 1 Nethserver-phonenehome 2024-11-21 5.5 Medium
A vulnerability was found in NethServer phonenehome. It has been rated as critical. This issue affects the function get_info/get_country_coor of the file server/index.php. The manipulation leads to sql injection. The identifier of the patch is 759c30b0ddd7d493836bbdf695cf71624b377391. It is recommended to apply a patch to fix this issue. The identifier VDB-218393 was assigned to this vulnerability.
CVE-2021-4301 1 Phpwcms 1 Phpwcms 2024-11-21 6.3 Medium
A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument $phpwcms['db_prepend'] leads to sql injection. The attack may be launched remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is identified as 77dafb6a8cc1015f0777daeb5792f43beef77a9d. It is recommended to upgrade the affected component. VDB-217418 is the identifier assigned to this vulnerability.
CVE-2021-4218 1 Linux 1 Linux Kernel 2024-11-21 5.5 Medium
A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specific to CentOS/RHEL.
CVE-2021-4208 1 Exportfeed 1 Exportfeed 2024-11-21 7.2 High
The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using it in a SQL statement, leading to a SQL injection vulnerability exploitable by high privilege users
CVE-2021-4194 1 Bookstackapp 1 Bookstack 2024-11-21 6.5 Medium
bookstack is vulnerable to Improper Access Control
CVE-2021-4171 1 Janeczku 1 Calibre-web 2024-11-21 9.8 Critical
calibre-web is vulnerable to Business Logic Errors
CVE-2021-4146 1 Pimcore 1 Pimcore 2024-11-21 4.3 Medium
Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.
CVE-2021-4133 1 Redhat 3 Keycloak, Red Hat Single Sign On, Rhosemc 2024-11-21 8.8 High
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
CVE-2021-4117 1 Yetiforce 1 Yetiforce Customer Relationship Management 2024-11-21 4.3 Medium
yetiforcecrm is vulnerable to Business Logic Errors