Latest CVE Feed
-
6.5
MEDIUMCVE-2022-42316
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, ... Read more
- EPSS Score: %0.05
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2024-31867
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommend... Read more
Affected Products : zeppelin- Published: Apr. 09, 2024
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2024-31868
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to ve... Read more
Affected Products : zeppelin- Published: Apr. 09, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-31866
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before ... Read more
Affected Products : zeppelin- Published: Apr. 09, 2024
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2025-31203
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, watchOS 11.4, visionOS 2.4. An attacker on the local network may be able ... Read more
- Published: Apr. 29, 2025
- Modified: May. 05, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-31202
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.... Read more
- Published: Apr. 29, 2025
- Modified: May. 05, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30445
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may cause a... Read more
- Published: Apr. 29, 2025
- Modified: May. 05, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2023-49959
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST reques... Read more
Affected Products : profinet-inspektor_nt- Published: Feb. 26, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-25730
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).... Read more
- Published: Feb. 23, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44053
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s... Read more
Affected Products : d8s-networking- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44052
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is... Read more
Affected Products : d8s-dates- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.... Read more
Affected Products : d8s-stats- EPSS Score: %0.14
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44050
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-json package. The affected version of d8s-htm is... Read more
Affected Products : d8s-networking- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44049
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected version of d8s-htm is... Read more
Affected Products : d8s-python- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44048
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.... Read more
Affected Products : d8s-urls- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2022-43359
Gifdec commit 1dcbae19363597314f6623010cc80abad4e47f7c was discovered to contain an out-of-bounds read in the function read_image_data. This vulnerability is triggered when parsing a crafted Gif file.... Read more
Affected Products : gifdec- EPSS Score: %0.04
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43352
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote.... Read more
Affected Products : sanitization_management_system- EPSS Score: %0.09
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2022-42788
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious application may be able to read sensitive location information.... Read more
Affected Products : macos- EPSS Score: %0.07
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.5
HIGHCVE-2022-25918
The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.... Read more
Affected Products : shescape- EPSS Score: %0.27
- Published: Oct. 27, 2022
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2019-8062
Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : after_effects- EPSS Score: %7.87
- Published: Aug. 14, 2019
- Modified: May. 05, 2025