Latest CVE Feed
-
9.8
CRITICALCVE-2022-45141
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the ... Read more
Affected Products : samba- EPSS Score: %0.35
- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2022-45174
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is n... Read more
Affected Products : vdesk- EPSS Score: %0.02
- Published: Apr. 14, 2023
- Modified: Feb. 07, 2025
-
9.8
CRITICAL- EPSS Score: %0.70
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.... Read more
Affected Products : webpanel- Actively Exploited
- EPSS Score: %94.33
- Published: Jan. 05, 2023
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2022-44797
btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking.... Read more
- EPSS Score: %0.21
- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44785
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.... Read more
Affected Products : appalti_\&_contratti- EPSS Score: %0.18
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-45062
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.... Read more
- EPSS Score: %0.75
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2018-11749
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.15
- Published: Aug. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44930
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.... Read more
- EPSS Score: %3.32
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2022-44559
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.28
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44558
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.28
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44456
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.... Read more
Affected Products : conprosys_hmi_system- EPSS Score: %40.12
- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2022-44581
Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.... Read more
- Published: May. 17, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2022-44544
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.... Read more
- EPSS Score: %0.28
- Published: Nov. 06, 2022
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2022-44117
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.... Read more
Affected Products : boa- EPSS Score: %0.07
- Published: Nov. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44193
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.... Read more
- EPSS Score: %0.39
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44038
Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.... Read more
- EPSS Score: %1.22
- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMa... Read more
Affected Products : debian_linux enterprise_linux_server openshift_container_platform oncommand_balance oncommand_performance_manager snapcenter oncommand_shift primavera_unifier virtualization virtualization_host +12 more products- EPSS Score: %77.34
- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43977
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.... Read more
- EPSS Score: %0.08
- Published: Jan. 17, 2023
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2022-44567
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution (internalVideoChatWindow.ts#L17). ... Read more
Affected Products : rocket.chat- EPSS Score: %1.31
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025