Latest CVE Feed
-
9.8
CRITICALCVE-2025-45616
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45615
Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45614
Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2022-34662
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher... Read more
Affected Products : dolphinscheduler- EPSS Score: %0.20
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
7.8
HIGHCVE-2022-32924
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.... Read more
- EPSS Score: %0.10
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
6.5
MEDIUMCVE-2022-32923
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose ... Read more
- EPSS Score: %0.19
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
7.8
HIGHCVE-2022-32903
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.... Read more
- EPSS Score: %0.18
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
4.7
MEDIUMCVE-2022-32895
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system.... Read more
Affected Products : macos- EPSS Score: %0.06
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
8.6
HIGHCVE-2022-32892
An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.... Read more
- EPSS Score: %0.14
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
8.6
HIGHCVE-2022-32890
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.... Read more
Affected Products : macos- EPSS Score: %0.23
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
2.4
LOWCVE-2022-32870
A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.... Read more
- EPSS Score: %0.08
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2022-31777
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in... Read more
Affected Products : spark- EPSS Score: %0.26
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2022-2572
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.... Read more
Affected Products : octopus_server- EPSS Score: %0.24
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
6.7
MEDIUMCVE-2025-1122
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challe... Read more
Affected Products : chrome_os- Published: Apr. 15, 2025
- Modified: May. 06, 2025
- Vuln Type: Memory Corruption
-
8.6
HIGHCVE-2022-3872
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_size. A malicious guest could use this... Read more
Affected Products : qemu- EPSS Score: %0.04
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-2711
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible b... Read more
- EPSS Score: %0.35
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2022-2387
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin dele... Read more
- EPSS Score: %0.16
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.1
CRITICALCVE-2024-25065
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.... Read more
Affected Products : ofbiz- Published: Feb. 29, 2024
- Modified: May. 05, 2025
-
7.1
HIGHCVE-2023-51747
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge ... Read more
Affected Products : james- Published: Feb. 27, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-51518
Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in pri... Read more
Affected Products : james- Published: Feb. 27, 2024
- Modified: May. 05, 2025