Latest CVE Feed
-
9.8
CRITICAL- EPSS Score: %4.53
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2022-44005
An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subsc... Read more
Affected Products : backclick- EPSS Score: %0.10
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44004
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.... Read more
Affected Products : backclick- EPSS Score: %0.22
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44003
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.... Read more
Affected Products : backclick- EPSS Score: %0.07
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
4.7
MEDIUMCVE-2022-43673
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database.... Read more
- EPSS Score: %0.04
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2022-43308
INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.... Read more
- EPSS Score: %0.03
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-43140
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via in... Read more
Affected Products : kkfileview- EPSS Score: %75.79
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-43138
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.10
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-42982
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can ... Read more
Affected Products : bkg_professional_ntripcaster- EPSS Score: %0.20
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2022-42904
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %13.03
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-3600
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.... Read more
- EPSS Score: %0.54
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-3336
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack... Read more
Affected Products : event_monster- EPSS Score: %0.17
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-38871
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.... Read more
Affected Products : free5gc- EPSS Score: %0.08
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20427
In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-24649
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having ac... Read more
Affected Products : wp_user_frontend- EPSS Score: %0.27
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
5.8
MEDIUMCVE-2024-20291
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked throug... Read more
Affected Products : nx-os nexus_3048 nexus_31108pc-v nexus_31108tc-v nexus_31128pq nexus_3132c-z nexus_3132q-v nexus_3132q-xl nexus_3164q nexus_3172pq +71 more products- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3457
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-21682
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira... Read more
Affected Products : assets_discovery_data_center- Published: Feb. 20, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3458
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3472
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication