Latest CVE Feed
-
6.0
MEDIUMCVE-2024-56662
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inli... Read more
Affected Products : linux_kernel- Published: Dec. 27, 2024
- Modified: May. 21, 2025
-
7.1
HIGHCVE-2024-50705
Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.... Read more
Affected Products : tripleplay- Published: Mar. 04, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-1955
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the ar... Read more
- Published: Mar. 04, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-48246
Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.... Read more
- Published: Mar. 05, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-37605
A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
6.1
MEDIUMCVE-2024-13868
The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against hig... Read more
Affected Products : url_shortener_\|_conversion_tracking_\|_ab_testing_\|_woocommerce- Published: Mar. 06, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-36831
A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
7.6
HIGHCVE-2025-0624
A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails... Read more
Affected Products : enterprise_linux openshift_container_platform grub2 international_components_for_unicode- Published: Feb. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2022-40942
Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.... Read more
- EPSS Score: %10.84
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-40929
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).... Read more
Affected Products : xxl-job- EPSS Score: %0.19
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-40878
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).... Read more
Affected Products : exam_reviewer_management_system- EPSS Score: %19.56
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-40877
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.... Read more
Affected Products : exam_reviewer_management_system- EPSS Score: %0.08
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2022-40817
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issu... Read more
Affected Products : zammad- EPSS Score: %0.14
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2022-40816
Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connecti... Read more
Affected Products : zammad- EPSS Score: %0.17
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-40497
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.... Read more
Affected Products : wazuh- EPSS Score: %2.13
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-40486
TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.... Read more
- EPSS Score: %1.72
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-40475
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.... Read more
- EPSS Score: %1.40
- Published: Sep. 29, 2022
- Modified: May. 21, 2025
-
7.2
HIGHCVE-2022-40354
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.... Read more
Affected Products : online_tours_\&_travels_management_system- EPSS Score: %0.09
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
7.8
HIGHCVE-2022-40126
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.... Read more
Affected Products : clash- EPSS Score: %0.08
- Published: Sep. 29, 2022
- Modified: May. 21, 2025
-
9.6
CRITICALCVE-2022-40083
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).... Read more
Affected Products : echo- EPSS Score: %71.35
- Published: Sep. 28, 2022
- Modified: May. 21, 2025