Show filters
1,184 Total Results
Displaying 331-340 of 1,184
Sort by:
Attacker Value
Unknown
CVE-2022-0158
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
vim is vulnerable to Heap-based Buffer Overflow
0
Attacker Value
Unknown
CVE-2022-0157
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2022-0156
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
vim is vulnerable to Use After Free
0
Attacker Value
Unknown
CVE-2022-21664
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-21663
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-21661
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2021-46142
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
0
Attacker Value
Unknown
CVE-2021-46141
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
0
Attacker Value
Unknown
CVE-2021-43816
Disclosure Date: January 05, 2022 (last updated February 23, 2025)
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.
0
Attacker Value
Unknown
CVE-2021-41819
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
0