Latest CVE Feed
-
9.8
CRITICALCVE-2022-43000
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
7.5
HIGHCVE-2022-42999
D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.... Read more
- EPSS Score: %2.25
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-42998
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-42992
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.... Read more
Affected Products : train_scheduler_app- EPSS Score: %0.17
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-42991
A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field.... Read more
Affected Products : simple_online_public_access_catalog- EPSS Score: %0.17
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
8.1
HIGHCVE-2022-42915
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. ... Read more
Affected Products : fedora curl macos h300s_firmware h500s_firmware h700s_firmware h410s_firmware universal_forwarder h300s h410s +3 more products- EPSS Score: %0.58
- Published: Oct. 29, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-42468
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no prot... Read more
Affected Products : flume- EPSS Score: %0.81
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2022-42055
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.... Read more
Affected Products : goodcloud- EPSS Score: %0.97
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
8.8
HIGHCVE-2022-40238
A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's profile is acces... Read more
Affected Products : vince- EPSS Score: %2.22
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-3394
The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the... Read more
Affected Products : wp_all_export- EPSS Score: %0.52
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-3393
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection... Read more
Affected Products : post_to_csv- EPSS Score: %3.66
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2022-3392
The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ... Read more
Affected Products : wp_humans.txt- EPSS Score: %0.71
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
8.8
HIGHCVE-2022-38060
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.... Read more
- EPSS Score: %0.02
- Published: Dec. 21, 2022
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2022-33757
An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of information on the scan target and/or the Nessus scan to unauthorized parties able to... Read more
Affected Products : nessus- EPSS Score: %0.22
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-33184
A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute arbitrary code ... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.03
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
8.8
HIGHCVE-2022-33183
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.87
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-33182
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “po... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.03
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2022-33181
An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”.... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.06
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
5.3
MEDIUMCVE-2022-2508
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.... Read more
Affected Products : octopus_server- EPSS Score: %0.29
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
6.1
MEDIUMCVE-2022-2190
The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers... Read more
Affected Products : envira_gallery- EPSS Score: %0.18
- Published: Oct. 31, 2022
- Modified: May. 07, 2025