Latest CVE Feed
-
6.1
MEDIUMCVE-2024-12096
The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : exhibit_to_wp_gallery- Published: Dec. 24, 2024
- Modified: May. 14, 2025
-
9.4
CRITICALCVE-2024-6235
Sensitive information disclosure in NetScaler Console... Read more
Affected Products : netscaler_console- Published: Jul. 10, 2024
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-42969
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been di... Read more
Affected Products : py- EPSS Score: %0.12
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.... Read more
Affected Products : gitea- EPSS Score: %0.16
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
5.3
MEDIUMCVE-2022-42961
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatur... Read more
Affected Products : wolfssl- EPSS Score: %0.23
- Published: Oct. 15, 2022
- Modified: May. 14, 2025
-
8.8
HIGHCVE-2022-42234
There is a file inclusion vulnerability in the template management module in UCMS 1.6... Read more
Affected Products : ucms- EPSS Score: %0.09
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-42071
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.... Read more
Affected Products : online_birth_certificate_management_system online_birth_certificate_management_system- EPSS Score: %0.10
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41601
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- EPSS Score: %0.01
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41600
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- EPSS Score: %0.01
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41585
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.... Read more
- EPSS Score: %0.03
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41584
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.... Read more
- EPSS Score: %0.03
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41583
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.... Read more
- EPSS Score: %0.08
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41582
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.... Read more
- EPSS Score: %0.08
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.1
CRITICALCVE-2022-41581
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.... Read more
- EPSS Score: %0.13
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.1
HIGHCVE-2022-41577
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability... Read more
- EPSS Score: %0.03
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41576
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.... Read more
- EPSS Score: %0.06
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
8.8
HIGHCVE-2022-41539
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : wedding_planner- EPSS Score: %0.15
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41323
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.... Read more
Affected Products : django- EPSS Score: %6.17
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
8.4
HIGHCVE-2022-33214
Memory corruption in display due to time-of-check time-of-use of metadata reserved size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware qcc5100_firmware +194 more products- EPSS Score: %0.06
- Published: Oct. 19, 2022
- Modified: May. 14, 2025
-
8.4
HIGHCVE-2022-33210
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto... Read more
Affected Products : qam8295p_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware sa6155p_firmware sa8145p_firmware sa8150p_firmware sa8155p_firmware +36 more products- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 14, 2025