Latest CVE Feed
-
7.5
HIGHCVE-2022-43766
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java... Read more
Affected Products : iotdb- EPSS Score: %0.40
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
6.7
MEDIUMCVE-2022-43750
drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.... Read more
- EPSS Score: %0.06
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43286
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.... Read more
Affected Products : njs- EPSS Score: %0.10
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.5
HIGHCVE-2022-43285
Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.... Read more
Affected Products : njs- EPSS Score: %0.08
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.1
HIGHCVE-2022-43280
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.... Read more
Affected Products : wabt- EPSS Score: %0.04
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43276
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.06
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43275
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.09
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43233
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.06
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2022-43232
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.06
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43003
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43002
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43001
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43000
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
7.5
HIGHCVE-2022-42999
D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.... Read more
- EPSS Score: %2.25
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-42998
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.... Read more
- EPSS Score: %0.38
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-42992
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.... Read more
Affected Products : train_scheduler_app- EPSS Score: %0.17
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-42991
A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field.... Read more
Affected Products : simple_online_public_access_catalog- EPSS Score: %0.17
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
8.1
HIGHCVE-2022-42915
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. ... Read more
Affected Products : fedora curl macos h300s_firmware h500s_firmware h700s_firmware h410s_firmware universal_forwarder h300s h410s +3 more products- EPSS Score: %0.58
- Published: Oct. 29, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-42468
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no prot... Read more
Affected Products : flume- EPSS Score: %0.81
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2022-42055
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.... Read more
Affected Products : goodcloud- EPSS Score: %0.97
- Published: Oct. 27, 2022
- Modified: May. 07, 2025