Latest CVE Feed
-
7.0
HIGHCVE-2022-33909
DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the Hdd... Read more
- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.0
HIGHCVE-2022-33908
DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the Sd... Read more
- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2022-33907
DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack... DMA transactions which are targeted at input buffers used for the software SMI hand... Read more
- EPSS Score: %0.04
- Published: Nov. 14, 2022
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2022-33906
DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by t... Read more
- EPSS Score: %0.04
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.0
HIGHCVE-2022-33905
DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corruption (a TOCTOU attack). DMA transactions which are targeted at input buffers used for the software SMI handler used by the AhciBusDxe... Read more
- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2022-32267
DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) DMA transactions which are targeted at input buffers used for the software SMI handler used by the SmmResou... Read more
- EPSS Score: %0.04
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2022-32266
DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. DMA attacks on the parameter buffer us... Read more
- EPSS Score: %0.05
- Published: Nov. 14, 2022
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2024-13874
The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : web_push_notifications- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-55210
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.... Read more
Affected Products : framework_\(linha_protheus\)- Published: Apr. 09, 2025
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2025-20934
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.... Read more
Affected Products : android- Published: Apr. 08, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-45947
An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component... Read more
Affected Products : online_banquet_booking_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
5.0
MEDIUMCVE-2025-25776
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or p... Read more
Affected Products : bus_ticket_booking_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2025-3955
A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of the file /edit_rpatient.php.php. The manipulation of the argument id/lastname leads to sql injection. It is ... Read more
Affected Products : patient_record_management_system- Published: Apr. 27, 2025
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-3968
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /api.php. The manipulation of the argument cat_id leads to sql injection. The attack can be... Read more
Affected Products : news_publishing_site_dashboard- Published: Apr. 27, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3969
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument ca... Read more
Affected Products : news_publishing_site_dashboard- Published: Apr. 27, 2025
- Modified: Apr. 30, 2025
-
3.5
LOWCVE-2025-0627
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the ... Read more
Affected Products : taxopress- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-4020
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack... Read more
Affected Products : old_age_home_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2023-21358
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Oct. 30, 2023
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-45391
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.... Read more
Affected Products : ns-nd_integration_performance_publisher- EPSS Score: %0.03
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-45390
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : loader.io- EPSS Score: %0.09
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025