Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-40485

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.... Read more

    Affected Products : wedding_planner
    • EPSS Score: %0.08
    • Published: Sep. 26, 2022
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-40432

    The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.... Read more

    Affected Products : d8s-strings
    • EPSS Score: %0.14
    • Published: Sep. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40471

    Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php... Read more

    • EPSS Score: %88.95
    • Published: Oct. 31, 2022
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2022-40242

    MegaRAC Default Credentials Vulnerability... Read more

    Affected Products : megarac_sp-x
    • EPSS Score: %0.13
    • Published: Dec. 05, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40628

    This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An un... Read more

    • EPSS Score: %1.49
    • Published: Sep. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40305

    A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.... Read more

    Affected Products : canto
    • EPSS Score: %0.40
    • Published: Sep. 09, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40630

    This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenti... Read more

    • EPSS Score: %0.78
    • Published: Sep. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40314

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.... Read more

    Affected Products : moodle
    • EPSS Score: %5.44
    • Published: Sep. 30, 2022
    • Modified: May. 20, 2025
  • 9.8

    CRITICAL
    CVE-2022-40296

    The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems. ... Read more

    Affected Products : php_point_of_sale
    • EPSS Score: %0.09
    • Published: Oct. 31, 2022
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2022-40347

    SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.... Read more

    Affected Products : intern_record_system
    • EPSS Score: %1.71
    • Published: Feb. 17, 2023
    • Modified: Mar. 18, 2025
  • 9.8

    CRITICAL
    CVE-2022-40429

    The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.... Read more

    Affected Products : d8s-ip-addresses
    • EPSS Score: %0.14
    • Published: Sep. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40138

    An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in ca... Read more

    Affected Products : hermes
    • EPSS Score: %0.40
    • Published: Oct. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40055

    An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.... Read more

    • EPSS Score: %0.12
    • Published: Oct. 17, 2022
    • Modified: May. 14, 2025
  • 9.8

    CRITICAL
    CVE-2022-40087

    Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more

    Affected Products : simple_college_website
    • EPSS Score: %0.21
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-40050

    ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.... Read more

    Affected Products : zfile
    • EPSS Score: %0.13
    • Published: Sep. 26, 2022
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-40118

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php.... Read more

    Affected Products : online_banking_system
    • EPSS Score: %0.08
    • Published: Sep. 23, 2022
    • Modified: May. 22, 2025
  • 9.8

    CRITICAL
    CVE-2022-3998

    A vulnerability, which was classified as critical, was found in MonikaBrzica scm. This affects an unknown part of the file uredi_korisnika.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The... Read more

    Affected Products : scm
    • EPSS Score: %0.05
    • Published: Nov. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-3980

    An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.... Read more

    Affected Products : mobile
    • EPSS Score: %88.02
    • Published: Nov. 16, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-40145

    This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialCon... Read more

    Affected Products : karaf
    • EPSS Score: %1.58
    • Published: Dec. 21, 2022
    • Modified: Apr. 15, 2025
  • 9.8

    CRITICAL
    CVE-2022-40144

    A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.... Read more

    Affected Products : windows apex_one
    • EPSS Score: %0.16
    • Published: Sep. 19, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 292507 Results