Latest CVE Feed
-
7.8
HIGHCVE-2024-0211
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file... Read more
Affected Products : wireshark- EPSS Score: %0.02
- Published: Jan. 03, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-21591
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the ... Read more
Affected Products : junos- EPSS Score: %23.48
- Published: Jan. 12, 2024
- Modified: May. 05, 2025
-
6.6
MEDIUMCVE-2023-6955
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated ... Read more
Affected Products : gitlab- EPSS Score: %0.03
- Published: Jan. 12, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2025-4026
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname/mobilenumber leads t... Read more
Affected Products : nipah_virus_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2023-3720
The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on the... Read more
Affected Products : upload_media_by_url- EPSS Score: %0.10
- Published: Aug. 30, 2023
- Modified: May. 05, 2025
-
4.8
MEDIUMCVE-2022-43372
Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.... Read more
Affected Products : emlog- EPSS Score: %0.08
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43109
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.... Read more
- EPSS Score: %1.04
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43108
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.... Read more
- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43105
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.... Read more
- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43104
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.... Read more
- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43103
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.... Read more
- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43102
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.... Read more
- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43063
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43062
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.09
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43061
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : online_tours_\&_travels_management_system- EPSS Score: %0.12
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-42744
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.... Read more
Affected Products : candidats- EPSS Score: %0.35
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.6
CRITICALCVE-2022-3708
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes... Read more
Affected Products : web_stories- EPSS Score: %0.35
- Published: Oct. 28, 2022
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2020-22524
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.... Read more
Affected Products : freeimage- EPSS Score: %0.15
- Published: Aug. 22, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2020-21427
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.... Read more
Affected Products : freeimage- EPSS Score: %0.36
- Published: Aug. 22, 2023
- Modified: May. 05, 2025
-
4.6
MEDIUMCVE-2024-40635
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow conditio... Read more
Affected Products : containerd- Published: Mar. 17, 2025
- Modified: May. 04, 2025