Latest CVE Feed
-
7.5
HIGHCVE-2022-41586
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.... Read more
- EPSS Score: %0.12
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-41580
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.... Read more
- EPSS Score: %0.14
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-41578
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.... Read more
- EPSS Score: %0.14
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-41472
74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.... Read more
Affected Products : 74cmsse- EPSS Score: %0.10
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.5
MEDIUMCVE-2022-41471
74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.... Read more
Affected Products : 74cmsse- EPSS Score: %0.08
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-41431
xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.... Read more
Affected Products : xzs- EPSS Score: %0.18
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-41139
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.... Read more
- EPSS Score: %0.11
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-40606
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.... Read more
Affected Products : caldera- EPSS Score: %0.11
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-40605
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.... Read more
Affected Products : caldera- EPSS Score: %0.11
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-40055
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.... Read more
- EPSS Score: %0.12
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
4.3
MEDIUMCVE-2022-3331
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object refe... Read more
Affected Products : gitlab- EPSS Score: %0.12
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
7.2
HIGHCVE-2022-3243
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin... Read more
Affected Products : import_all_pages\,_post_types\,_products\,_orders\,_and_users_as_xml_\&_csv- EPSS Score: %0.29
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.9
MEDIUMCVE-2022-3206
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.... Read more
Affected Products : passster- EPSS Score: %0.10
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.5
MEDIUMCVE-2022-3165
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a den... Read more
- EPSS Score: %0.10
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2024-3353
A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/mod_reports/index.php. The manipulation of the argument categ/end leads ... Read more
Affected Products : aplaya_beach_resort_online_reservation_system- Published: Apr. 05, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2024-2569
A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin-manage-user.php. The manipulation leads to execution after redirect. The at... Read more
- Published: Mar. 18, 2024
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2025-29824
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Actively Exploited
- Published: Apr. 08, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-3244
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create User Page. The ma... Read more
- Published: Apr. 04, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3151
A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql injection. The atta... Read more
- Published: Apr. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3143
A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The manipulation of the argument visname/address leads to sql injection. It is... Read more
- Published: Apr. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection