Latest CVE Feed
-
6.1
MEDIUMCVE-2023-48928
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.... Read more
Affected Products : system_sentinel_anyware- Published: Dec. 08, 2023
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2023-48421
In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no ad... Read more
Affected Products : android- Published: Dec. 08, 2023
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2023-46932
Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box.... Read more
Affected Products : gpac- Published: Dec. 09, 2023
- Modified: May. 27, 2025
-
6.1
MEDIUMCVE-2023-46494
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid function in admin/productGrid/Grid.jsx.... Read more
Affected Products : evershop- Published: Dec. 08, 2023
- Modified: May. 27, 2025
-
8.8
HIGHCVE-2023-43743
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database ... Read more
Affected Products : mx-se_firmware mx-se_ii_firmware mx-e_firmware mx-virtual_firmware mx250_firmware mx30_firmware mx-se mx-se_ii mx-e mx-virtual +2 more products- Published: Dec. 08, 2023
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2022-40935
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.... Read more
Affected Products : online_pet_shop_web_application- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2022-40934
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id... Read more
Affected Products : online_pet_shop_web_application- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2022-40933
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.... Read more
Affected Products : online_pet_shop_web_application- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2022-40932
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.... Read more
- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2022-40447
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.... Read more
Affected Products : zzcms- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2022-40446
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.... Read more
Affected Products : zzcms- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
8.8
HIGHCVE-2022-40298
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system an... Read more
Affected Products : airmedia- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-38573
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.... Read more
Affected Products : network_inventory_explorer- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
8.2
HIGHCVE-2022-35408
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the ... Read more
Affected Products : insydeh2o- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35039
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35038
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35037
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35036
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e1fc8.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35035
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35034
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025