Latest CVE Feed
-
8.8
HIGHCVE-2024-24350
File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.... Read more
Affected Products : e-sic_livre- EPSS Score: %1.87
- Published: Feb. 08, 2024
- Modified: May. 08, 2025
-
4.2
MEDIUMCVE-2024-24255
A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.... Read more
Affected Products : px4_drone_autopilot- EPSS Score: %0.04
- Published: Feb. 06, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-24216
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.... Read more
Affected Products : zentao- EPSS Score: %6.84
- Published: Feb. 08, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-24186
Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.... Read more
Affected Products : jsish- EPSS Score: %1.08
- Published: Feb. 07, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-24112
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.... Read more
Affected Products : xmall- EPSS Score: %81.13
- Published: Feb. 06, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-24003
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can con... Read more
Affected Products : jsherp- EPSS Score: %0.10
- Published: Feb. 08, 2024
- Modified: May. 08, 2025
-
8.8
HIGHCVE-2024-22515
Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.... Read more
Affected Products : agent_dvr- EPSS Score: %10.17
- Published: Feb. 06, 2024
- Modified: May. 08, 2025
-
7.8
HIGHCVE-2024-22012
there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. ... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Feb. 07, 2024
- Modified: May. 08, 2025
-
5.1
MEDIUMCVE-2023-33770
Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2022-43435
Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : 360_fireline- EPSS Score: %0.20
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
5.3
MEDIUMCVE-2022-43434
Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : neuvector_vulnerability_scanner- EPSS Score: %0.21
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2022-43433
Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : screenrecorder- EPSS Score: %0.22
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2022-43432
Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : xframium_builder- EPSS Score: %0.20
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2022-43431
Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : compuware_strobe_measurement- EPSS Score: %0.14
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2022-43430
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : compuware_topaz_for_total_test- EPSS Score: %0.26
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2022-43429
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file ... Read more
- EPSS Score: %0.13
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
5.3
MEDIUMCVE-2022-43428
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the... Read more
- EPSS Score: %0.21
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2022-43427
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : compuware_topaz_for_total_test- EPSS Score: %0.13
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
5.3
MEDIUMCVE-2022-43426
Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.... Read more
Affected Products : s3_explorer- EPSS Score: %0.14
- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2022-43425
Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke... Read more
Affected Products : custom_checkbox_parameter- EPSS Score: %3.71
- Published: Oct. 19, 2022
- Modified: May. 08, 2025