๐จ CVE-2022-25852
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.
๐@cveNotify
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.
๐@cveNotify
Learn more about rhel:7 with Snyk Open Source Vulnerability Database
Improper Preservation of Permissions in kernel-doc | CVE-2022-0330 | Snyk
High severity (7) Improper Preservation of Permissions in kernel-doc | CVE-2022-0330
๐จ CVE-2022-25345
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
๐@cveNotify
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Denial of Service (DoS) in @discordjs/opus | CVE-2022-25345 | Snyk
High severity (7.5) Denial of Service (DoS) in @discordjs/opus | CVE-2022-25345
๐จ CVE-2022-22138
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Denial of Service (DoS) in fast-string-search | CVE-2022-22138 | Snyk
High severity (7.5) Denial of Service (DoS) in fast-string-search | CVE-2022-22138
๐จ CVE-2022-21213
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
Snyk Vulnerability Database
Prototype Pollution in org.webjars.npm:mout | CVE-2022-21213 | Snyk
Fix high severity Prototype Pollution vulnerability affecting org.webjars.npm:mout package, versions [0,]
๐จ CVE-2021-40902
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
๐@cveNotify
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
๐@cveNotify
GitHub
Stored XSS in Index ยท Issue #57 ยท flatCore/flatCore-CMS
Describe the bug Cross Site Scripting (XSS) via save Exclude URLs To Reproduce Steps to reproduce the behavior: Login to flatcore CMS Click on 'Create new Page' after click '...
๐จ CVE-2022-0786
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users
๐@cveNotify
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users
๐@cveNotify
WPScan
KiviCare < 2.3.9 - Unauthenticated SQLi
See details on KiviCare < 2.3.9 - Unauthenticated SQLi CVE 2022-0786. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-0827
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
๐@cveNotify
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
๐@cveNotify
Wpscan
WPScan: WordPress Security
A WordPress vulnerability database for WordPress core security vulnerabilities, plugin vulnerabilities and theme vulnerabilities.
๐จ CVE-2022-0863
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
๐@cveNotify
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
๐@cveNotify
WPScan
WP SVG Icons <= 3.2.3 - Admin+ Remote Code Execution (RCE)
See details on WP SVG Icons <= 3.2.3 - Admin+ Remote Code Execution (RCE) CVE 2022-0863. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-0885
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
๐@cveNotify
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
๐@cveNotify
WPScan
Member Hero <= 1.0.9 - Unauthenticated RCE
See details on Member Hero <= 1.0.9 - Unauthenticated RCE CVE 2022-0885. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-1202
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
๐@cveNotify
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
๐@cveNotify
WPScan
WP-CRM <= 1.2.1 - CSV Injection
See details on WP-CRM <= 1.2.1 - CSV Injection CVE 2022-1202. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-22138
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Denial of Service (DoS) in fast-string-search | CVE-2022-22138 | Snyk
High severity (7.5) Denial of Service (DoS) in fast-string-search | CVE-2022-22138
๐จ CVE-2022-21213
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
Snyk Vulnerability Database
Prototype Pollution in org.webjars.npm:mout | CVE-2022-21213 | Snyk
Fix high severity Prototype Pollution vulnerability affecting org.webjars.npm:mout package, versions [0,]
๐จ CVE-2022-1595
The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request
๐@cveNotify
The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request
๐@cveNotify
WPScan
HC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL Disclosure
See details on HC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL Disclosure CVE 2022-1595. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-1549
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.
๐@cveNotify
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.
๐@cveNotify
๐จ CVE-2022-0745
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body
๐@cveNotify
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body
๐@cveNotify
๐จ CVE-2022-31400
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
๐@cveNotify
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
๐@cveNotify
YouTube
Helpdeskz - Stored XSS - Email Field
๐จ CVE-2022-31756
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
๐@cveNotify
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
๐@cveNotify
๐จ CVE-2022-31755
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
๐@cveNotify
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
๐@cveNotify
๐จ CVE-2022-31751
The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
๐@cveNotify
The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
๐@cveNotify
๐จ CVE-2021-46814
The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.
๐@cveNotify
The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.
๐@cveNotify
๐จ CVE-2022-31762
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
๐@cveNotify
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
๐@cveNotify
๐1