Latest CVE Feed
-
9.8
CRITICALCVE-2022-42154
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : 74cmsse- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-42149
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.... Read more
Affected Products : kkfileview- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-42147
kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.... Read more
Affected Products : kkfileview- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
7.2
HIGHCVE-2022-42143
Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.... Read more
Affected Products : open_source_sacco_management_system- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
7.2
HIGHCVE-2022-42142
Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php.... Read more
Affected Products : online_tours_and_travels_management_system- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
8.8
HIGHCVE-2022-42029
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.... Read more
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41594
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41593
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
3.4
LOWCVE-2022-41592
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41588
The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2022-41586
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-41580
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-41578
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-41472
74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.... Read more
Affected Products : 74cmsse- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.5
MEDIUMCVE-2022-41471
74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.... Read more
Affected Products : 74cmsse- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-41431
xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.... Read more
Affected Products : xzs- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-41139
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.... Read more
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-40606
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.... Read more
Affected Products : caldera- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-40605
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.... Read more
Affected Products : caldera- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-40055
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.... Read more
- Published: Oct. 17, 2022
- Modified: May. 14, 2025