Latest CVE Feed
-
9.8
CRITICAL- Published: Dec. 11, 2023
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2023-42908
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.... Read more
Affected Products : macos- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2023-42884
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. An app may be able to disclose kernel memory.... Read more
- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2023-41117
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFI... Read more
Affected Products : postgres_advanced_server- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2023-36652
A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.... Read more
Affected Products : cryptospike- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2023-28465
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen ... Read more
Affected Products : hl7_fhir_core- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-41320
Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a net... Read more
Affected Products : system_recovery- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
6.1
MEDIUMCVE-2022-41319
A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9.7).... Read more
Affected Products : desktop_and_laptop_option- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-40869
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-40865
Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-40716
HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and ... Read more
Affected Products : consul- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-40188
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-40089
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
6.1
MEDIUMCVE-2022-40088
Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted paylo... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-40087
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-38936
An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.... Read more
Affected Products : pbc- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-37235
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2022-37234
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.... Read more
- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-36944
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase c... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2022-35024
OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.... Read more
Affected Products : otfcc- Published: Sep. 22, 2022
- Modified: May. 27, 2025