Latest CVE Feed
-
9.8
CRITICALCVE-2022-44544
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.... Read more
- EPSS Score: %0.26
- Published: Nov. 06, 2022
- Modified: May. 02, 2025
-
7.8
HIGHCVE-2022-42919
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from ... Read more
- EPSS Score: %0.02
- Published: Nov. 07, 2022
- Modified: May. 02, 2025
-
9.1
CRITICALCVE-2022-42905
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)... Read more
Affected Products : wolfssl- EPSS Score: %3.96
- Published: Nov. 07, 2022
- Modified: May. 02, 2025
-
7.5
HIGHCVE-2022-42707
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.... Read more
Affected Products : mahara- EPSS Score: %0.18
- Published: Nov. 06, 2022
- Modified: May. 02, 2025
-
7.8
HIGHCVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G s... Read more
- EPSS Score: %0.03
- Published: Nov. 06, 2022
- Modified: May. 02, 2025
-
7.6
HIGHCVE-2022-3721
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.... Read more
Affected Products : froxlor- EPSS Score: %0.12
- Published: Nov. 04, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-38582
Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.... Read more
Affected Products : anti-virus- EPSS Score: %0.08
- Published: Nov. 04, 2022
- Modified: May. 02, 2025
-
3.5
LOWCVE-2022-38163
A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below. Drag and drop operation by user on address bar could lead to a spoofing of the address bar.... Read more
Affected Products : safe- EPSS Score: %0.15
- Published: Nov. 07, 2022
- Modified: May. 02, 2025
-
5.5
MEDIUMCVE-2022-37911
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume sy... Read more
- EPSS Score: %0.13
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-37910
A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system. ... Read more
- EPSS Score: %0.16
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2022-37909
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond... Read more
- EPSS Score: %0.10
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2022-37908
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller. ... Read more
- EPSS Score: %0.09
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
7.5
HIGHCVE-2022-37907
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the im... Read more
- EPSS Score: %0.14
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
8.1
HIGHCVE-2022-37906
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system. ... Read more
- EPSS Score: %0.19
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
8.8
HIGHCVE-2022-37905
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating s... Read more
- EPSS Score: %0.45
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
8.8
HIGHCVE-2022-37904
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating s... Read more
- EPSS Score: %0.25
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-37901
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. ... Read more
- EPSS Score: %0.43
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-37899
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. ... Read more
- EPSS Score: %0.43
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-37898
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. ... Read more
- EPSS Score: %0.43
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2022-37897
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerab... Read more
- EPSS Score: %1.28
- Published: Dec. 12, 2022
- Modified: May. 02, 2025