The Wayback Machine - https://web.archive.org/web/20220207223242/https://nvd.nist.gov/
U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.



The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2020-29607 - A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
    Published: December 16, 2020; 10:15:12 AM -0500

    V3.1: 7.2 HIGH
    V2.0: 6.5 MEDIUM

  • CVE-2021-45471 - In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
    Published: December 23, 2021; 9:15:07 PM -0500

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM

  • CVE-2021-45472 - In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
    Published: December 23, 2021; 9:15:07 PM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-45473 - In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
    Published: December 23, 2021; 9:15:07 PM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2018-7434 - zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.
    Published: February 23, 2018; 10:29:00 PM -0500

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM

  • CVE-2021-43848 - h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server-side implementation of h2o can be misguided to treat uninitialized ... read CVE-2021-43848
    Published: February 01, 2022; 8:15:09 AM -0500

    V3.1: 5.9 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-44882 - D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
    Published: February 03, 2022; 9:15:08 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2021-24814 - The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't... read CVE-2021-24814
    Published: February 01, 2022; 8:15:08 AM -0500

    V3.1: 9.6 CRITICAL
    V2.0: 6.8 MEDIUM

  • CVE-2021-44881 - D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
    Published: February 03, 2022; 9:15:07 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2022-23833 - An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
    Published: February 02, 2022; 9:15:07 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2022-22818 - The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
    Published: February 02, 2022; 9:15:07 PM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-44880 - D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a... read CVE-2021-44880
    Published: February 03, 2022; 9:15:07 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2021-42633 - PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
    Published: February 02, 2022; 1:15:07 PM -0500

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM

  • CVE-2022-23357 - mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
    Published: February 02, 2022; 10:15:06 PM -0500

    V3.1: 9.1 CRITICAL
    V2.0: 6.4 MEDIUM

  • CVE-2022-23871 - Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description param... read CVE-2022-23871
    Published: February 02, 2022; 10:15:06 PM -0500

    V3.1: 5.4 MEDIUM
    V2.0: 3.5 LOW

  • CVE-2022-23603 - iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. ... read CVE-2022-23603
    Published: February 01, 2022; 6:15:11 AM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2020-8562 - As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service provid... read CVE-2020-8562
    Published: February 01, 2022; 6:15:10 AM -0500

    V3.1: 3.1 LOW
    V2.0: 3.5 LOW

  • CVE-2022-21724 - pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or proper... read CVE-2022-21724
    Published: February 02, 2022; 7:15:08 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2008-2944 - Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the ... read CVE-2008-2944
    Published: June 30, 2008; 5:41:00 PM -0400

    V2.0: 4.9 MEDIUM

  • CVE-2022-21659 - Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing acc... read CVE-2022-21659
    Published: January 31, 2022; 4:15:09 PM -0500

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM