Latest CVE Feed
-
7.5
HIGHCVE-2022-44549
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.... Read more
- EPSS Score: %0.10
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2022-44548
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.... Read more
- EPSS Score: %0.03
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2022-44318
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall.... Read more
Affected Products : picoc- EPSS Score: %0.06
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2022-44317
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall.... Read more
Affected Products : picoc- EPSS Score: %0.03
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2022-43120
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.... Read more
- EPSS Score: %0.45
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-43058
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.10
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2022-43031
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.... Read more
Affected Products : dedecms- EPSS Score: %0.31
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.2
HIGHCVE-2022-37900
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. ... Read more
- EPSS Score: %0.43
- Published: Dec. 12, 2022
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2022-33322
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS ... Read more
Affected Products : mac-587if-e_firmware mac-587if2-e_firmware mac-507if-e_firmware mac-588if-e_firmware s-mac-002if_firmware ma-ew85s-e_firmware ma-ew85s-uk_firmware msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1_firmware msy-gp10\/13\/15\/18\/20\/24vfk-sg1_firmware msz-ap25\/35\/42\/50vgk-e1_firmware +228 more products- EPSS Score: %0.78
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-27674
Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.... Read more
- EPSS Score: %0.08
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-23831
Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.... Read more
- EPSS Score: %0.20
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2021-26391
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.... Read more
- EPSS Score: %0.03
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2021-26360
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code ... Read more
Affected Products : radeon_pro_software radeon_software enterprise_driver radeon_rx_6300m radeon_rx_6400 radeon_rx_6500_xt radeon_rx_6500m radeon_rx_6600 radeon_rx_6600_xt radeon_rx_6600m +26 more products- EPSS Score: %0.04
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2023-0878
Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.... Read more
- EPSS Score: %0.09
- Published: Feb. 17, 2023
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-29514
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : leptoncms- Published: Apr. 02, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-29515
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
5.4
MEDIUMCVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it ... Read more
Affected Products : moodle- Published: Mar. 22, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-29374
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.... Read more
Affected Products : moodle- Published: Mar. 21, 2024
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2024-24520
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.... Read more
Affected Products : leptoncms- Published: Mar. 21, 2024
- Modified: May. 01, 2025
-
8.3
HIGHCVE-2023-4990
Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.... Read more
- EPSS Score: %0.20
- Published: Oct. 11, 2023
- Modified: May. 01, 2025