Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2022-35056

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0478.... Read more

    Affected Products : otfcc
    • EPSS Score: %0.20
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 6.5

    MEDIUM
    CVE-2022-35055

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0473.... Read more

    Affected Products : otfcc
    • EPSS Score: %0.20
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 6.5

    MEDIUM
    CVE-2022-35054

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.... Read more

    Affected Products : otfcc
    • EPSS Score: %0.20
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 6.5

    MEDIUM
    CVE-2022-35053

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.... Read more

    Affected Products : otfcc
    • EPSS Score: %0.22
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 6.5

    MEDIUM
    CVE-2022-35052

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b84b1.... Read more

    Affected Products : otfcc
    • EPSS Score: %0.22
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 5.5

    MEDIUM
    CVE-2022-32931

    This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information.... Read more

    Affected Products : macos
    • EPSS Score: %0.13
    • Published: Jan. 10, 2024
    • Modified: May. 15, 2025
  • 7.8

    HIGH
    CVE-2022-2985

    In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.13
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 5.5

    MEDIUM
    CVE-2022-2984

    In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • EPSS Score: %0.03
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 7.5

    HIGH
    CVE-2022-2963

    A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.... Read more

    Affected Products : enterprise_linux fedora jasper
    • EPSS Score: %0.10
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 6.5

    MEDIUM
    CVE-2022-2850

    A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This ... Read more

    • EPSS Score: %0.25
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 8.1

    HIGH
    CVE-2022-2780

    In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.... Read more

    Affected Products : octopus_server
    • EPSS Score: %0.29
    • Published: Oct. 14, 2022
    • Modified: May. 15, 2025
  • 8.4

    HIGH
    CVE-2022-25661

    Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile... Read more

    • EPSS Score: %0.08
    • Published: Oct. 19, 2022
    • Modified: May. 15, 2025
  • 7.8

    HIGH
    CVE-2022-25660

    Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile... Read more

    • EPSS Score: %0.08
    • Published: Oct. 19, 2022
    • Modified: May. 15, 2025
  • 4.8

    MEDIUM
    CVE-2024-7056

    The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for... Read more

    Affected Products : wpforms
    • Published: Nov. 25, 2024
    • Modified: May. 15, 2025
  • 4.8

    MEDIUM
    CVE-2024-10471

    The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more

    Affected Products : everest_forms
    • Published: Nov. 26, 2024
    • Modified: May. 15, 2025
  • 9.8

    CRITICAL
    CVE-2024-46054

    OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.... Read more

    Affected Products : openvidreview
    • Published: Nov. 27, 2024
    • Modified: May. 15, 2025
  • 7.6

    HIGH
    CVE-2024-3405

    The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more

    Affected Products : wp_prayer
    • Published: May. 15, 2024
    • Modified: May. 15, 2025
  • 8.8

    HIGH
    CVE-2024-3406

    The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more

    Affected Products : wp_prayer
    • Published: May. 15, 2024
    • Modified: May. 15, 2025
  • 5.3

    MEDIUM
    CVE-2024-3407

    The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks... Read more

    Affected Products : wp_prayer
    • Published: May. 15, 2024
    • Modified: May. 15, 2025
  • 2.4

    LOW
    CVE-2024-3629

    The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more

    Affected Products : hl_twitter
    • Published: May. 15, 2024
    • Modified: May. 15, 2025
Showing 20 of 291737 Results