Latest CVE Feed
-
5.5
MEDIUMCVE-2021-47275
In the Linux kernel, the following vulnerability has been resolved: bcache: avoid oversized read request in cache missing code path In the cache missing code path of cached device, if a proper location from the internal B+ tree is matched for a cache mi... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2021-47276
In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a bug on arm64 caused a bad ip address to be used for updating into a nop in ftrace_init(), but the error... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2021-47277
In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mechanism for accessing guest memory translates a guest physical address (gpa) to a host virtual address us... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2024-49559
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized acce... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2021-47282
In the Linux kernel, the following vulnerability has been resolved: spi: bcm2835: Fix out-of-bounds access with more than 4 slaves Commit 571e31fa60b3 ("spi: bcm2835: Cache CS register value for ->prepare_message()") limited the number of slaves to 3 at... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2021-47286
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads the channel ID from the event ring element sent by the device which can be any value between 0 and 255.... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2024-26870
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102 A call to listxattr() with a buffer size = 0 returns the actual size of the buffer needed for a subsequent call. When size > ... Read more
- Published: Apr. 17, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-20345
A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-s... Read more
- Published: Mar. 06, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2022-45383
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Admi... Read more
Affected Products : support_core- EPSS Score: %0.08
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-45382
Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to edit build display n... Read more
Affected Products : naginator- EPSS Score: %1.46
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2022-44378
Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.... Read more
Affected Products : automotive_shop_management_system- EPSS Score: %0.07
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICAL- EPSS Score: %4.53
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2022-44005
An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subsc... Read more
Affected Products : backclick- EPSS Score: %0.10
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44004
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.... Read more
Affected Products : backclick- EPSS Score: %0.22
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44003
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.... Read more
Affected Products : backclick- EPSS Score: %0.07
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
4.7
MEDIUMCVE-2022-43673
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database.... Read more
- EPSS Score: %0.04
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2022-43308
INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.... Read more
- EPSS Score: %0.03
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-43140
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via in... Read more
Affected Products : kkfileview- EPSS Score: %75.79
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-43138
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.10
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-42982
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can ... Read more
Affected Products : bkg_professional_ntripcaster- EPSS Score: %0.20
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025