Latest CVE Feed
-
4.0
MEDIUMCVE-2023-28362
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Lo... Read more
Affected Products : actionpack- Published: Jan. 09, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2022-43222
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.... Read more
Affected Products : open5gs- EPSS Score: %0.08
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.5
HIGHCVE-2022-43221
open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.... Read more
Affected Products : open5gs- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
6.1
MEDIUMCVE-2022-43985
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.... Read more
Affected Products : airflow- EPSS Score: %2.53
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
6.1
MEDIUMCVE-2022-43982
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.... Read more
Affected Products : airflow- EPSS Score: %4.97
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
5.4
MEDIUMCVE-2022-43670
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in ... Read more
Affected Products : sling_cms- EPSS Score: %0.18
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43355
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service.... Read more
Affected Products : sanitization_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43354
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request.... Read more
Affected Products : sanitization_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43353
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.... Read more
Affected Products : sanitization_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43331
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43330
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43329
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-43328
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.09
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
5.5
MEDIUMCVE-2022-43255
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.... Read more
Affected Products : gpac- EPSS Score: %0.03
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
5.5
MEDIUMCVE-2022-43254
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.... Read more
Affected Products : gpac- EPSS Score: %0.03
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-43253
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.11
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-43252
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.11
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-43250
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.15
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-43249
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.13
- Published: Nov. 02, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-43248
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.... Read more
- EPSS Score: %0.11
- Published: Nov. 02, 2022
- Modified: May. 02, 2025