Latest CVE Feed
-
9.8
CRITICALCVE-2022-20391
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000... Read more
Affected Products : android- EPSS Score: %0.34
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-54148
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.... Read more
Affected Products : gogs- Published: Dec. 23, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2022-20385
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: Androi... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-20381
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-20387
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324... Read more
Affected Products : android- EPSS Score: %0.34
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1950
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection... Read more
Affected Products : youzify- EPSS Score: %66.09
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1812
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.... Read more
Affected Products : publify- EPSS Score: %1.97
- Published: Jan. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1795
Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1813
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.... Read more
Affected Products : rengine- EPSS Score: %3.84
- Published: May. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1799
Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.... Read more
Affected Products : google_play_services_software_development_kit- EPSS Score: %0.16
- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1737
Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a de... Read more
- EPSS Score: %0.03
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1715
Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.... Read more
Affected Products : facturascripts- EPSS Score: %0.32
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1664
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that includ... Read more
- EPSS Score: %0.48
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35121
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.... Read more
Affected Products : novel-plus- EPSS Score: %0.23
- Published: Aug. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1574
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server... Read more
Affected Products : html2wp- EPSS Score: %73.67
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1700
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enab... Read more
- EPSS Score: %0.08
- Published: Sep. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1453
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attac... Read more
Affected Products : rsvpmaker- EPSS Score: %6.42
- Published: May. 10, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-1391
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.... Read more
Affected Products : cab_fare_calculator- EPSS Score: %66.71
- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1471
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing unt... Read more
Affected Products : snakeyaml- EPSS Score: %93.85
- Published: Dec. 01, 2022
- Modified: Jun. 18, 2025
-
9.8
CRITICALCVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: ... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +1 more products- Actively Exploited
- EPSS Score: %94.46
- Published: May. 05, 2022
- Modified: Apr. 02, 2025