Latest CVE Feed
-
8.1
HIGHCVE-2024-40405
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-40404
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-1106
The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : shariff_wrapper- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-45195
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the... Read more
- EPSS Score: %0.14
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
4.7
MEDIUMCVE-2022-45194
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.... Read more
Affected Products : cbrn-analysis- EPSS Score: %0.09
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-45182
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.... Read more
Affected Products : pi-star_digital_voice_dashboard- EPSS Score: %0.44
- Published: Nov. 11, 2022
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2022-45130
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so t... Read more
Affected Products : obsidian- EPSS Score: %0.39
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-45129
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2... Read more
Affected Products : payara- EPSS Score: %1.57
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
9.1
CRITICALCVE-2022-44727
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).... Read more
Affected Products : eu_cookie_law_gdpr- EPSS Score: %0.29
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-44561
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.... Read more
- EPSS Score: %0.07
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-44560
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.... Read more
- EPSS Score: %0.07
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44559
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.28
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44558
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.28
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-44557
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.... Read more
- EPSS Score: %0.09
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-44555
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.... Read more
- EPSS Score: %0.09
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-44554
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.... Read more
- EPSS Score: %0.09
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-44553
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.... Read more
- EPSS Score: %0.08
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44089
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.... Read more
Affected Products : espcms- EPSS Score: %2.11
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44088
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.... Read more
Affected Products : espcms- EPSS Score: %37.86
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44087
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.... Read more
Affected Products : espcms- EPSS Score: %2.11
- Published: Nov. 10, 2022
- Modified: May. 01, 2025