Latest CVE Feed
-
9.6
CRITICALCVE-2024-7760
aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all e... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.6
CRITICALCVE-2024-7102
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.... Read more
Affected Products : gitlab- Published: Feb. 13, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2024-6779
Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 16, 2024
- Modified: Mar. 20, 2025
-
9.6
CRITICALCVE-2024-6522
The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This makes it possible for authenticated attackers, with Subscriber-level acces... Read more
- Published: Aug. 07, 2024
- Modified: Mar. 01, 2025
-
9.6
CRITICALCVE-2023-20192
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write c... Read more
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-0488
Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-10096
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated att... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-10285
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated a... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2022-4924
Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
Affected Products : chrome- Published: Jul. 29, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-4135
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: Nov. 25, 2022
- Modified: Mar. 12, 2025
-
9.6
CRITICALCVE-2022-46733
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site scripting in its backup services. An attacker could take advantage of this vulnerability to execute arbitrary commands. ... Read more
Affected Products : real-time_location_system_studio- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-46332
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 ... Read more
Affected Products : enterprise_protection- Published: Dec. 06, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-42447
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request. ... Read more
Affected Products : hcl_compass- Published: Apr. 02, 2023
- Modified: Feb. 19, 2025
-
9.6
CRITICALCVE-2022-42711
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.... Read more
Affected Products : whatsup_gold- Published: Oct. 12, 2022
- Modified: May. 15, 2025
-
9.6
CRITICALCVE-2022-41654
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerabili... Read more
Affected Products : ghost- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-40083
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).... Read more
Affected Products : echo- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
9.6
CRITICALCVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Actively Exploited
- Published: Sep. 26, 2022
- Modified: Jul. 30, 2025
-
9.6
CRITICALCVE-2022-39214
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and... Read more
Affected Products : itop- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-38339
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.... Read more
Affected Products : fme_server- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-37830
Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : webjet_cms- Published: Oct. 19, 2023
- Modified: Nov. 21, 2024