Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-52883

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.... Read more

    Affected Products : one_voice_operations_center
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-52882

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.... Read more

    Affected Products : one_voice_operations_center
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-52881

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.... Read more

    Affected Products : one_voice_operations_center
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 4.8

    MEDIUM
    CVE-2024-40410

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 7.3

    HIGH
    CVE-2024-40408

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-40407

    A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 8.1

    HIGH
    CVE-2024-40405

    Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2024-40404

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-1106

    The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more

    Affected Products : shariff_wrapper
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-45195

    SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the... Read more

    Affected Products : simplex_chat simplexmq
    • EPSS Score: %0.14
    • Published: Nov. 12, 2022
    • Modified: May. 01, 2025
  • 4.7

    MEDIUM
    CVE-2022-45194

    CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.... Read more

    Affected Products : cbrn-analysis
    • EPSS Score: %0.09
    • Published: Nov. 12, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-45182

    Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.... Read more

    Affected Products : pi-star_digital_voice_dashboard
    • EPSS Score: %0.44
    • Published: Nov. 11, 2022
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2022-45130

    Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so t... Read more

    Affected Products : obsidian
    • EPSS Score: %0.39
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-45129

    Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2... Read more

    Affected Products : payara
    • EPSS Score: %1.57
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 9.1

    CRITICAL
    CVE-2022-44727

    The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).... Read more

    Affected Products : eu_cookie_law_gdpr
    • EPSS Score: %0.29
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44561

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.07
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-44560

    The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.07
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44559

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.28
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-44558

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.28
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44557

    The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.09
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
Showing 20 of 291058 Results