Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.1

    HIGH
    CVE-2024-40405

    Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2024-40404

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-1106

    The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more

    Affected Products : shariff_wrapper
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-45195

    SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the... Read more

    Affected Products : simplex_chat simplexmq
    • EPSS Score: %0.14
    • Published: Nov. 12, 2022
    • Modified: May. 01, 2025
  • 4.7

    MEDIUM
    CVE-2022-45194

    CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.... Read more

    Affected Products : cbrn-analysis
    • EPSS Score: %0.09
    • Published: Nov. 12, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-45182

    Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.... Read more

    Affected Products : pi-star_digital_voice_dashboard
    • EPSS Score: %0.44
    • Published: Nov. 11, 2022
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2022-45130

    Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so t... Read more

    Affected Products : obsidian
    • EPSS Score: %0.39
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-45129

    Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2... Read more

    Affected Products : payara
    • EPSS Score: %1.57
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 9.1

    CRITICAL
    CVE-2022-44727

    The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).... Read more

    Affected Products : eu_cookie_law_gdpr
    • EPSS Score: %0.29
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44561

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.07
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-44560

    The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.07
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44559

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.28
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44558

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.28
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44557

    The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.09
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44555

    The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.09
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44554

    The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.09
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-44553

    The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.08
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44089

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.... Read more

    Affected Products : espcms
    • EPSS Score: %2.11
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44088

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.... Read more

    Affected Products : espcms
    • EPSS Score: %37.86
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44087

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.... Read more

    Affected Products : espcms
    • EPSS Score: %2.11
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
Showing 20 of 291021 Results