Latest CVE Feed
-
9.6
CRITICALCVE-2022-41654
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerabili... Read more
Affected Products : ghost- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-40083
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).... Read more
Affected Products : echo- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
9.6
CRITICALCVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Actively Exploited
- Published: Sep. 26, 2022
- Modified: Jul. 30, 2025
-
9.6
CRITICALCVE-2022-39214
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and... Read more
Affected Products : itop- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-38339
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.... Read more
Affected Products : fme_server- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-37830
Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : webjet_cms- Published: Oct. 19, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-36990
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write... Read more
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-36180
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.... Read more
Affected Products : fusiondirectory- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.6
CRITICALCVE-2021-21146
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-32271
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is... Read more
Affected Products : realplayer- Published: Jun. 03, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-31105
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or ... Read more
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-30690
A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to s... Read more
Affected Products : avideo- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-2014
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.... Read more
Affected Products : drawio- Published: Jun. 09, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-5704
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted ... Read more
- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-28755
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary n... Read more
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for A... Read more
- Actively Exploited
- Published: Dec. 22, 2022
- Modified: Mar. 21, 2025
-
9.6
CRITICALCVE-2021-21223
Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-25772
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript... Read more
Affected Products : mautic- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-25395
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.... Read more
Affected Products : cosmetics_and_beauty_product_online_store- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-24799
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a... Read more
Affected Products : wire-webapp- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024