Latest CVE Feed
-
6.5
MEDIUMCVE-2022-40716
HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and ... Read more
Affected Products : consul- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-40188
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-40089
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.1
MEDIUMCVE-2022-40088
Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted paylo... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-40087
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-38936
An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.... Read more
Affected Products : pbc- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-37235
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2022-37234
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.... Read more
- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-36944
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase c... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35024
OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-34026
ICEcoder v8.1 allows attackers to execute a directory traversal.... Read more
Affected Products : icecoder- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
5.9
MEDIUMCVE-2022-33682
TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication conn... Read more
Affected Products : pulsar- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2022-32849
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to access sensitive... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2022-32814
A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-31937
Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.... Read more
- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
8.2
HIGHCVE-2022-29181
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or r... Read more
- Published: May. 20, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default fro... Read more
Affected Products : pinot- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
8.8
HIGHCVE-2021-3187
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies ... Read more
- Published: Dec. 11, 2023
- Modified: May. 27, 2025
-
8.1
HIGHCVE-2020-36604
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.... Read more
Affected Products : hoek- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2018-16153
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.... Read more
Affected Products : opencast- Published: Dec. 12, 2023
- Modified: May. 27, 2025