Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2025-47153

    Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BI... Read more

    Affected Products :
    • Published: May. 01, 2025
    • Modified: May. 02, 2025
  • 8.8

    HIGH
    CVE-2023-41715

    SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel. ... Read more

    Affected Products : sonicos tz270 tz270w tz370 tz370w tz470 tz470w tz570 tz570p tz570w +51 more products
    • EPSS Score: %0.28
    • Published: Oct. 17, 2023
    • Modified: May. 02, 2025
  • 10.0

    CRITICAL
    CVE-2023-40455

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.... Read more

    Affected Products : macos
    • EPSS Score: %0.27
    • Published: Sep. 27, 2023
    • Modified: May. 02, 2025
  • 9.8

    CRITICAL
    CVE-2023-34051

    VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. ... Read more

    Affected Products : aria_operations_for_logs
    • EPSS Score: %57.74
    • Published: Oct. 20, 2023
    • Modified: May. 02, 2025
  • 8.9

    HIGH
    CVE-2022-44724

    The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.... Read more

    Affected Products : handy_macros_for_confluence
    • EPSS Score: %0.08
    • Published: Nov. 04, 2022
    • Modified: May. 02, 2025
  • 9.8

    CRITICAL
    CVE-2022-44544

    Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.... Read more

    Affected Products : ubuntu_linux mahara
    • EPSS Score: %0.26
    • Published: Nov. 06, 2022
    • Modified: May. 02, 2025
  • 7.8

    HIGH
    CVE-2022-42919

    Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from ... Read more

    Affected Products : fedora python
    • EPSS Score: %0.02
    • Published: Nov. 07, 2022
    • Modified: May. 02, 2025
  • 9.1

    CRITICAL
    CVE-2022-42905

    In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)... Read more

    Affected Products : wolfssl
    • EPSS Score: %3.96
    • Published: Nov. 07, 2022
    • Modified: May. 02, 2025
  • 7.5

    HIGH
    CVE-2022-42707

    In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.... Read more

    Affected Products : mahara
    • EPSS Score: %0.18
    • Published: Nov. 06, 2022
    • Modified: May. 02, 2025
  • 7.8

    HIGH
    CVE-2022-40284

    A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G s... Read more

    Affected Products : fedora debian_linux ntfs-3g
    • EPSS Score: %0.03
    • Published: Nov. 06, 2022
    • Modified: May. 02, 2025
  • 7.6

    HIGH
    CVE-2022-3721

    Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.... Read more

    Affected Products : froxlor
    • EPSS Score: %0.12
    • Published: Nov. 04, 2022
    • Modified: May. 02, 2025
  • 6.5

    MEDIUM
    CVE-2022-38582

    Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.... Read more

    Affected Products : anti-virus
    • EPSS Score: %0.08
    • Published: Nov. 04, 2022
    • Modified: May. 02, 2025
  • 3.5

    LOW
    CVE-2022-38163

    A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below. Drag and drop operation by user on address bar could lead to a spoofing of the address bar.... Read more

    Affected Products : safe
    • EPSS Score: %0.15
    • Published: Nov. 07, 2022
    • Modified: May. 02, 2025
  • 5.5

    MEDIUM
    CVE-2022-37911

    Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume sy... Read more

    Affected Products : arubaos sd-wan
    • EPSS Score: %0.13
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
  • 6.5

    MEDIUM
    CVE-2022-37910

    A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system. ... Read more

    Affected Products : arubaos sd-wan
    • EPSS Score: %0.16
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
  • 5.3

    MEDIUM
    CVE-2022-37909

    Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond... Read more

    Affected Products : arubaos sd-wan
    • EPSS Score: %0.10
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
  • 6.5

    MEDIUM
    CVE-2022-37908

    An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller. ... Read more

    Affected Products : arubaos sd-wan 7005 7008 7010 7024 7030 7205 7210 7220 +2 more products
    • EPSS Score: %0.09
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
  • 7.5

    HIGH
    CVE-2022-37907

    A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the im... Read more

    Affected Products : arubaos sd-wan 7005 7008 7010 7024 7030 7205 7210 7220 +2 more products
    • EPSS Score: %0.14
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
  • 8.1

    HIGH
    CVE-2022-37906

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system. ... Read more

    Affected Products : arubaos sd-wan
    • EPSS Score: %0.19
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
  • 8.8

    HIGH
    CVE-2022-37905

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating s... Read more

    Affected Products : arubaos sd-wan 7005 7008 7010 7024 7030 7205 7210 7220 +2 more products
    • EPSS Score: %0.45
    • Published: Dec. 12, 2022
    • Modified: May. 02, 2025
Showing 20 of 291162 Results