Latest CVE Feed
-
5.5
MEDIUMCVE-2022-4697
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possib... Read more
Affected Products : profilepress- EPSS Score: %0.08
- Published: Dec. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-34494
rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Jun. 26, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-24130
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.... Read more
- EPSS Score: %0.13
- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-23198
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of ... Read more
- EPSS Score: %0.66
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-23197
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASL... Read more
- EPSS Score: %2.04
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-23195
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASL... Read more
- EPSS Score: %2.04
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22648
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to read restricted memory.... Read more
- EPSS Score: %0.16
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22002
Windows User Account Profile Picture Denial of Service Vulnerability... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 windows_10_1809 windows_10_20h2 +10 more products- EPSS Score: %0.26
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-21998
Windows Common Log File System Driver Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 +14 more products- EPSS Score: %0.44
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1622
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.... Read more
- EPSS Score: %0.11
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0907
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.... Read more
- EPSS Score: %0.07
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0851
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the act... Read more
- EPSS Score: %0.03
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-14710
Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- EPSS Score: %0.18
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38865
Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.... Read more
- EPSS Score: %0.03
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38863
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.... Read more
- EPSS Score: %0.04
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38861
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.... Read more
- EPSS Score: %0.04
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38850
The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c.... Read more
- EPSS Score: %0.03
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-47437
In the Linux kernel, the following vulnerability has been resolved: iio: adis16475: fix deadlock on frequency set With commit 39c024b51b560 ("iio: adis16475: improve sync scale mode handling"), two deadlocks were introduced: 1) The call to 'adis_write_... Read more
Affected Products : linux_kernel- Published: May. 22, 2024
- Modified: Jan. 10, 2025
-
5.5
MEDIUMCVE-2021-46766
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.... Read more
Affected Products : ryzen_threadripper_pro_3945wx_firmware ryzen_threadripper_pro_3955wx_firmware ryzen_threadripper_pro_3975wx_firmware ryzen_threadripper_pro_3995wx_firmware epyc_9124_firmware epyc_9174f_firmware epyc_9184x_firmware epyc_9224_firmware epyc_9254_firmware epyc_9274f_firmware +46 more products- EPSS Score: %0.02
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46045
GPAC 1.0.1 is affected by: Abort failed. The impact is: cause a denial of service (context-dependent).... Read more
Affected Products : gpac- EPSS Score: %0.08
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024