Latest CVE Feed
-
8.2
HIGHCVE-2022-29278
Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory. This issue was discovered by Insyde during securit... Read more
Affected Products : kernel- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2022-29277
Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addres... Read more
- EPSS Score: %0.07
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
8.2
HIGHCVE-2022-29276
SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: vers... Read more
Affected Products : kernel- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
8.2
HIGHCVE-2022-29275
In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in: Kern... Read more
Affected Products : kernel- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20460
In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20459
In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20428
In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2022-1581
The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.... Read more
Affected Products : wp-polls- EPSS Score: %0.05
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-1579
The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.... Read more
Affected Products : login_block_ips- EPSS Score: %0.16
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2022-1578
The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack... Read more
Affected Products : my_wpdb- EPSS Score: %0.32
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2022-0421
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due ... Read more
Affected Products : five_star_restaurant_reservations- EPSS Score: %0.52
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2021-47252
In the Linux kernel, the following vulnerability has been resolved: batman-adv: Avoid WARN_ON timing related checks The soft/batadv interface for a queued OGM can be changed during the time the OGM was queued for transmission and when the OGM is actuall... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2021-47255
In the Linux kernel, the following vulnerability has been resolved: kvm: LAPIC: Restore guard to prevent illegal APIC register access Per the SDM, "any access that touches bytes 4 through 15 of an APIC register may cause undefined behavior and must not ... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.6
HIGHCVE-2025-46252
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kofimokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.... Read more
Affected Products : message_filter_for_contact_form_7- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-46253
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit allows Stored XSS. This issue affects GutenKit: from n/a through 2.2.2.... Read more
Affected Products : gutenkit- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2021-47256
In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: make sure wait for page writeback in memory_failure Our syzkaller trigger the "BUG_ON(!list_empty(&inode->i_wb_list))" in clear_inode: kernel BUG at fs/inode.c:519... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2021-47258
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix error handling of scsi_host_alloc() After device is initialized via device_initialize(), or its name is set via dev_set_name(), the device has to be freed via put_device... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2021-47261
In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix initializing CQ fragments buffer The function init_cq_frag_buf() can be called to initialize the current CQ fragments buffer cq->buf, or the temporary cq->resize_buf that i... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-46254
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.10.0.... Read more
Affected Products : visual_composer_website_builder- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2021-47263
In the Linux kernel, the following vulnerability has been resolved: gpio: wcd934x: Fix shift-out-of-bounds error bit-mask for pins 0 to 4 is BIT(0) to BIT(4) however we ended up with BIT(n - 1) which is not right, and this was caught by below usban chec... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025