Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2023-48928

    Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.... Read more

    Affected Products : system_sentinel_anyware
    • Published: Dec. 08, 2023
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-48421

    In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no ad... Read more

    Affected Products : android
    • Published: Dec. 08, 2023
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-46932

    Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box.... Read more

    Affected Products : gpac
    • Published: Dec. 09, 2023
    • Modified: May. 27, 2025
  • 6.1

    MEDIUM
    CVE-2023-46494

    Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid function in admin/productGrid/Grid.jsx.... Read more

    Affected Products : evershop
    • Published: Dec. 08, 2023
    • Modified: May. 27, 2025
  • 8.8

    HIGH
    CVE-2023-43743

    A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database ... Read more

    • Published: Dec. 08, 2023
    • Modified: May. 27, 2025
  • 7.2

    HIGH
    CVE-2022-40935

    Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.... Read more

    Affected Products : online_pet_shop_web_application
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.2

    HIGH
    CVE-2022-40934

    Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id... Read more

    Affected Products : online_pet_shop_web_application
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.2

    HIGH
    CVE-2022-40933

    Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.... Read more

    Affected Products : online_pet_shop_web_application
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.2

    HIGH
    CVE-2022-40932

    In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.... Read more

    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.2

    HIGH
    CVE-2022-40447

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.... Read more

    Affected Products : zzcms
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.2

    HIGH
    CVE-2022-40446

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.... Read more

    Affected Products : zzcms
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 8.8

    HIGH
    CVE-2022-40298

    Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system an... Read more

    Affected Products : airmedia
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-38573

    10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.... Read more

    Affected Products : network_inventory_explorer
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 8.2

    HIGH
    CVE-2022-35408

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the ... Read more

    Affected Products : insydeh2o
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-35039

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.... Read more

    Affected Products : otfcc
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-35038

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.... Read more

    Affected Products : otfcc
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-35037

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.... Read more

    Affected Products : otfcc
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-35036

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e1fc8.... Read more

    Affected Products : otfcc
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-35035

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.... Read more

    Affected Products : otfcc
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-35034

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.... Read more

    Affected Products : otfcc
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
Showing 20 of 292913 Results