• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-46530
2022-12-24
N/A
7.5 HIGH
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.
CVE-2022-4653
2023-01-24
N/A
5.4 MEDIUM
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
CVE-2022-4651
2023-02-06
N/A
5.4 MEDIUM
The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
CVE-2022-46505
2023-01-26
N/A
7.5 HIGH
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
CVE-2022-46503
2023-01-20
N/A
5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /admin/register.php of Online Student Enrollment System v1.0 allows attackers to execute arbitrary web scripts via a crafted payload injected into the name parameter.
CVE-2022-46502
2023-01-23
N/A
9.8 CRITICAL
Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php.
CVE-2022-4650
Hashbar, Hasthemes
Contact_form_7_widget_for_elementor_page_builder_&_gutenberg_blocks, Coupon_zen, Ever_compare, Extensions_for_cf7, Free_woocommerce_theme_99fy_extension, Hashbar, Ht_event, Ht_mega_-_absolute_addons_for_elementor_page_builder, Ht_politic, Ht_portfolio
2023-01-30
N/A
5.4 MEDIUM
The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
CVE-2022-46496
2023-02-14
N/A
5.9 MEDIUM
BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.
CVE-2022-46493
2022-12-30
N/A
9.8 CRITICAL
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.
CVE-2022-46492
2022-12-30
N/A
6.5 MEDIUM
nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary.
« Previous 1 … 8,956 8,957 8,958 8,959 8,960 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE