Latest CVE Feed
-
6.5
MEDIUMCVE-2024-0365
The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.... Read more
Affected Products : fancy_product_designer- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-5174
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-st... Read more
- EPSS Score: %0.31
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2023-42852
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.... Read more
- EPSS Score: %1.83
- Published: Oct. 25, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-41068
An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7. A user may be able to elevate privileges.... Read more
- EPSS Score: %0.02
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-41063
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.... Read more
- EPSS Score: %0.04
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-40419
The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to gain elevated privileges.... Read more
- EPSS Score: %0.02
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2023-40418
An authentication issue was addressed with improved state management. This issue is fixed in watchOS 10. An Apple Watch Ultra may not lock when using the Depth app.... Read more
- EPSS Score: %0.10
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-40125
In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo... Read more
Affected Products : android- EPSS Score: %0.00
- Published: Oct. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-40120
In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne... Read more
Affected Products : android- EPSS Score: %0.00
- Published: Oct. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-40116
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i... Read more
Affected Products : android- EPSS Score: %0.00
- Published: Oct. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-32377
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.... Read more
Affected Products : macos- EPSS Score: %0.14
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2023-21266
In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i... Read more
Affected Products : android- EPSS Score: %0.00
- Published: Oct. 06, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44542
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.... Read more
Affected Products : lesspipe- EPSS Score: %0.13
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.3
HIGHCVE-2022-43990
Password recovery vulnerability in SICK SIM1012 Partnumber 1098146 with firmware version <2.2.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. Th... Read more
- EPSS Score: %0.91
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.3
HIGHCVE-2022-43989
Password recovery vulnerability in SICK SIM2x00 (ARM) Partnumber 1092673 and 1081902 with firmware version < 1.2.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery m... Read more
Affected Products : sim2000-2p04g10_firmware sim2500-2p03g10_firmware sim2000-2p04g10 sim2500-2p03g10- EPSS Score: %0.91
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43362
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.... Read more
Affected Products : senayan_library_management_system- EPSS Score: %0.08
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
4.8
MEDIUMCVE-2022-43361
Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.... Read more
Affected Products : senayan_library_management_system- EPSS Score: %0.08
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2022-43241
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.15
- Published: Nov. 02, 2022
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2022-43240
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.11
- Published: Nov. 02, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43127
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 05, 2025