Latest CVE Feed
-
9.4
CRITICALCVE-2024-6235
Sensitive information disclosure in NetScaler Console... Read more
Affected Products : netscaler_console- Published: Jul. 10, 2024
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-42969
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been di... Read more
Affected Products : py- EPSS Score: %0.12
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.... Read more
Affected Products : gitea- EPSS Score: %0.16
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
5.3
MEDIUMCVE-2022-42961
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatur... Read more
Affected Products : wolfssl- EPSS Score: %0.23
- Published: Oct. 15, 2022
- Modified: May. 14, 2025
-
8.8
HIGHCVE-2022-42234
There is a file inclusion vulnerability in the template management module in UCMS 1.6... Read more
Affected Products : ucms- EPSS Score: %0.09
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-42071
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.... Read more
Affected Products : online_birth_certificate_management_system online_birth_certificate_management_system- EPSS Score: %0.10
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41601
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- EPSS Score: %0.01
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41600
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- EPSS Score: %0.01
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41585
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.... Read more
- EPSS Score: %0.03
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41584
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.... Read more
- EPSS Score: %0.03
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41583
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.... Read more
- EPSS Score: %0.08
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41582
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.... Read more
- EPSS Score: %0.08
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.1
CRITICALCVE-2022-41581
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.... Read more
- EPSS Score: %0.13
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.1
HIGHCVE-2022-41577
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability... Read more
- EPSS Score: %0.03
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41576
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.... Read more
- EPSS Score: %0.06
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
8.8
HIGHCVE-2022-41539
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : wedding_planner- EPSS Score: %0.15
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41323
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.... Read more
Affected Products : django- EPSS Score: %6.17
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
8.4
HIGHCVE-2022-33214
Memory corruption in display due to time-of-check time-of-use of metadata reserved size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware qcc5100_firmware +194 more products- EPSS Score: %0.06
- Published: Oct. 19, 2022
- Modified: May. 14, 2025
-
8.4
HIGHCVE-2022-33210
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto... Read more
Affected Products : qam8295p_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware sa6155p_firmware sa8145p_firmware sa8150p_firmware sa8155p_firmware +36 more products- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 14, 2025
-
9.9
CRITICALCVE-2022-2992
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.... Read more
Affected Products : gitlab- EPSS Score: %93.59
- Published: Oct. 17, 2022
- Modified: May. 14, 2025