• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-28450
2022-05-04
N/A
5.4 MEDIUM
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
CVE-2022-2845
2022-10-25
N/A
7.8 HIGH
Buffer Over-read in GitHub repository vim/vim prior to 9.0.0218.
CVE-2022-28449
2022-05-04
N/A
6.1 MEDIUM
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
CVE-2022-28448
2022-05-04
N/A
5.4 MEDIUM
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
CVE-2022-28445
2022-05-02
N/A
6.5 MEDIUM
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
CVE-2022-28444
2022-05-02
N/A
7.5 HIGH
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
CVE-2022-28443
2022-05-02
N/A
9.1 CRITICAL
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
CVE-2022-28440
2022-05-02
N/A
8.8 HIGH
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-2844
2022-08-19
N/A
6.1 MEDIUM
A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2 of the component Calendar Handler. The manipulation of the argument Subject/Location/Description leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206487.
CVE-2022-28439
2022-04-28
N/A
9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4.
« Previous 1 … 10,192 10,193 10,194 10,195 10,196 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE