Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2022-41349

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.... Read more

    Affected Products : collaboration
    • EPSS Score: %0.38
    • Published: Oct. 12, 2022
    • Modified: May. 15, 2025
  • 6.1

    MEDIUM
    CVE-2022-41348

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.... Read more

    Affected Products : collaboration
    • EPSS Score: %0.44
    • Published: Oct. 12, 2022
    • Modified: May. 15, 2025
  • 5.3

    MEDIUM
    CVE-2022-41316

    HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieve... Read more

    Affected Products : vault
    • EPSS Score: %0.10
    • Published: Oct. 12, 2022
    • Modified: May. 15, 2025
  • 9.8

    CRITICAL
    CVE-2022-40871

    Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.... Read more

    Affected Products : dolibarr_erp\/crm
    • EPSS Score: %78.76
    • Published: Oct. 12, 2022
    • Modified: May. 15, 2025
  • 9.8

    CRITICAL
    CVE-2022-40664

    Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.... Read more

    Affected Products : shiro
    • EPSS Score: %0.52
    • Published: Oct. 12, 2022
    • Modified: May. 15, 2025
  • 8.8

    HIGH
    CVE-2022-40469

    iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.... Read more

    Affected Products : ikuaios
    • EPSS Score: %4.21
    • Published: Oct. 12, 2022
    • Modified: May. 15, 2025
  • 8.0

    HIGH
    CVE-2022-40187

    Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user... Read more

    • EPSS Score: %0.04
    • Published: Oct. 13, 2022
    • Modified: May. 15, 2025
  • 5.5

    MEDIUM
    CVE-2022-39120

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.03
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 5.5

    MEDIUM
    CVE-2022-39113

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.07
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.8

    HIGH
    CVE-2022-39109

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.13
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.8

    HIGH
    CVE-2022-39108

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.13
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.8

    HIGH
    CVE-2022-39107

    In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.05
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 5.5

    MEDIUM
    CVE-2022-39105

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.03
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 5.5

    MEDIUM
    CVE-2022-39103

    In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.03
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.8

    HIGH
    CVE-2022-39080

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.13
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 8.1

    HIGH
    CVE-2022-39064

    An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay (i.e. resend) the same frame multiple times, the bulb performs a factory reset. This causes the bulb to lose configuration information abo... Read more

    • EPSS Score: %0.06
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.5

    HIGH
    CVE-2022-39011

    The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.08
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.5

    HIGH
    CVE-2022-38998

    The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.11
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.5

    HIGH
    CVE-2022-38985

    The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.08
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.5

    HIGH
    CVE-2022-38984

    The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.11
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
Showing 20 of 291712 Results