Latest CVE Feed
-
7.8
HIGHCVE-2023-52752
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() Skip SMB sessions that are being teared down (e.g. @ses->ses_status == SES_EXITING) in cifs_debug_data_proc_show() to ... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42939
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.14
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42938
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.15
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42937
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.15
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42936
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.14
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42935
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.15
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42934
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.15
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2022-42933
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.06
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-41711
Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.... Read more
Affected Products : badaso- EPSS Score: %4.18
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2022-3644
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.... Read more
- EPSS Score: %0.03
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
7.7
HIGHCVE-2022-3570
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure ... Read more
- EPSS Score: %0.01
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2022-36783
AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another ... Read more
Affected Products : fireflow- EPSS Score: %0.07
- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2024-13381
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is di... Read more
Affected Products : calculated_fields_form- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-31172
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4151
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/pass-bwdates-reports-details.php. The manipulation of the argument fromdate leads to ... Read more
Affected Products : curfew_e-pass_management_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4152
A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. It i... Read more
Affected Products : online_birth_certificate_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-21530
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jan. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-21545
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jan. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Denial of Service
-
6.0
MEDIUMCVE-2025-21551
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris ... Read more
- Published: Jan. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-24399
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log i... Read more
- Published: Jan. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication