Latest CVE Feed
-
7.8
HIGHCVE-2023-28215
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.... Read more
Affected Products : macos- EPSS Score: %0.08
- Published: Sep. 06, 2023
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2023-28209
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.... Read more
Affected Products : macos- EPSS Score: %0.08
- Published: Sep. 06, 2023
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-45196
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabric with Raft prevents exploitation via a locking mechanism and a check for n... Read more
Affected Products : fabric- EPSS Score: %0.07
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2022-44319
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c when called from ExpressionParseFunctionCall.... Read more
Affected Products : picoc- EPSS Score: %0.03
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2022-44312
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator.... Read more
Affected Products : picoc- EPSS Score: %0.06
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
8.1
HIGHCVE-2022-44311
html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html f... Read more
Affected Products : html2xhtml- EPSS Score: %1.81
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-43945
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single a... Read more
Affected Products : linux_kernel active_iq_unified_manager h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s +2 more products- EPSS Score: %0.42
- Published: Nov. 04, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-43343
N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c.... Read more
Affected Products : n-prolog- EPSS Score: %2.12
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.4
MEDIUMCVE-2022-43144
A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.94
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2022-41757
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to obtain write access to read-only memory, or obtain access to already freed memory. This affects Valhall r29p0 through r38p1 bef... Read more
Affected Products : valhall_gpu_kernel_driver- EPSS Score: %0.25
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2022-41434
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.... Read more
Affected Products : web_interface- EPSS Score: %0.11
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
4.8
MEDIUMCVE-2022-41433
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php.... Read more
Affected Products : web_interface- EPSS Score: %0.09
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
4.8
MEDIUMCVE-2022-41432
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php.... Read more
Affected Products : web_interface- EPSS Score: %0.09
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-37109
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the... Read more
Affected Products : camp- EPSS Score: %1.31
- Published: Nov. 14, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-37015
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access ... Read more
Affected Products : endpoint_detection_and_response- EPSS Score: %0.41
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-34825
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a r... Read more
- EPSS Score: %3.40
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-34824
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earl... Read more
- EPSS Score: %3.81
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-33321
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Condit... Read more
- EPSS Score: %0.58
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.8
MEDIUMCVE-2022-32618
In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User... Read more
- EPSS Score: %0.05
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.8
MEDIUMCVE-2022-32617
In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User... Read more
- EPSS Score: %0.05
- Published: Nov. 08, 2022
- Modified: May. 01, 2025