Latest CVE Feed
-
7.0
HIGHCVE-2025-20671
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09... Read more
- Published: May. 05, 2025
- Modified: May. 07, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2025-20668
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS... Read more
- Published: May. 05, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2022-43231
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.09
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43230
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.... Read more
Affected Products : simple_cold_storage_managment_system- EPSS Score: %0.09
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43229
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.... Read more
Affected Products : simple_cold_storage_managment_system- EPSS Score: %0.09
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43228
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.... Read more
Affected Products : barangay_management_system- EPSS Score: %0.06
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-43170
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injec... Read more
Affected Products : rukovoditel- EPSS Score: %6.54
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-42189
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.... Read more
Affected Products : emlog- EPSS Score: %0.94
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.5
HIGHCVE-2022-41575
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.... Read more
Affected Products : enterprise- EPSS Score: %0.20
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-41310
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.14
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-41309
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.14
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-40690
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : bookstack- EPSS Score: %0.46
- Published: Oct. 24, 2022
- Modified: May. 07, 2025
-
7.5
HIGHCVE-2022-3639
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have... Read more
Affected Products : gitlab- EPSS Score: %0.03
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2022-3627
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sou... Read more
- EPSS Score: %0.02
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2022-3344
A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
6.8
MEDIUMCVE-2022-3018
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog ... Read more
Affected Products : gitlab- EPSS Score: %0.09
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2022-39837
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointe... Read more
Affected Products : diagnostic_log_and_trace- EPSS Score: %0.03
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2022-39836
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based ... Read more
Affected Products : diagnostic_log_and_trace- EPSS Score: %0.03
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-38580
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).... Read more
Affected Products : skipper- EPSS Score: %48.90
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-37915
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability could allow a... Read more
Affected Products : aruba_edgeconnect_enterprise_orchestrator- EPSS Score: %1.95
- Published: Oct. 28, 2022
- Modified: May. 07, 2025