Latest CVE Feed
-
7.1
HIGHCVE-2022-32831
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected terminatio... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-32828
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-32825
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-32805
The issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to access sensitive user information.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.8
HIGHCVE-2022-32801
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.... Read more
Affected Products : macos- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-32800
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.9
MEDIUMCVE-2022-32799
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak sensitive information.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
6.5
MEDIUMCVE-2022-32220
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.... Read more
Affected Products : rocket.chat- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2022-32219
An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (... Read more
Affected Products : rocket.chat- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2022-2987
The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers ... Read more
Affected Products : ldap_wp_login_\/_active_directory_integration- Published: Sep. 26, 2022
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2022-2853
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2022-2852
Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2022-22629
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2022-0080
mruby is vulnerable to Heap-based Buffer Overflow... Read more
Affected Products : mruby- Published: Jan. 02, 2022
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2021-41819
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.... Read more
Affected Products : ruby enterprise_linux fedora debian_linux leap software_collections linux_enterprise cgi factory- Published: Jan. 01, 2022
- Modified: May. 22, 2025
-
8.4
HIGHCVE-2021-30337
Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, S... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +410 more products- Published: Jan. 03, 2022
- Modified: May. 22, 2025
-
7.2
HIGHCVE-2025-2257
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the ... Read more
Affected Products : total_upkeep- Published: Mar. 26, 2025
- Modified: May. 22, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2024-9545
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.16.4 due to insufficient input sanitizati... Read more
- Published: Dec. 21, 2024
- Modified: May. 22, 2025
-
6.4
MEDIUMCVE-2024-12588
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on us... Read more
- Published: Dec. 21, 2024
- Modified: May. 22, 2025
-
5.4
MEDIUMCVE-2024-12042
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type valida... Read more
Affected Products : mstore_api- Published: Dec. 13, 2024
- Modified: May. 22, 2025