Latest CVE Feed
-
8.8
HIGHCVE-2022-40402
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.... Read more
Affected Products : wedding_planner- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
2.7
LOWCVE-2022-40199
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure informati... Read more
Affected Products : ec-cube- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
7.2
HIGHCVE-2022-40099
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.... Read more
Affected Products : online_tours_\&_travels_management_system- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
7.2
HIGHCVE-2022-40098
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.... Read more
Affected Products : online_tours_\&_travels_management_system- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
7.2
HIGHCVE-2022-40097
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.... Read more
Affected Products : online_tours_and_travels_management_system- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-40050
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.... Read more
Affected Products : zfile- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3055
Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2022-3054
Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2022-3053
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3052
Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3043
Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3042
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3041
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3040
Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3039
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2022-38975
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.... Read more
Affected Products : ec-cube- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-37346
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image f... Read more
Affected Products : product_image_bulk_upload- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-30004
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..... Read more
Affected Products : online_market_place_site- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-2998
Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.... Read more
Affected Products : chrome- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2021-41437
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025