Latest CVE Feed
-
7.8
HIGHCVE-2021-47282
In the Linux kernel, the following vulnerability has been resolved: spi: bcm2835: Fix out-of-bounds access with more than 4 slaves Commit 571e31fa60b3 ("spi: bcm2835: Cache CS register value for ->prepare_message()") limited the number of slaves to 3 at... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2021-47286
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads the channel ID from the event ring element sent by the device which can be any value between 0 and 255.... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2024-26870
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102 A call to listxattr() with a buffer size = 0 returns the actual size of the buffer needed for a subsequent call. When size > ... Read more
- Published: Apr. 17, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2022-45383
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Admi... Read more
Affected Products : support_core- EPSS Score: %0.08
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-45382
Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to edit build display n... Read more
Affected Products : naginator- EPSS Score: %1.46
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2022-44378
Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.... Read more
Affected Products : automotive_shop_management_system- EPSS Score: %0.07
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICAL- EPSS Score: %4.53
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2022-44005
An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subsc... Read more
Affected Products : backclick- EPSS Score: %0.10
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44004
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.... Read more
Affected Products : backclick- EPSS Score: %0.22
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44003
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.... Read more
Affected Products : backclick- EPSS Score: %0.07
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
4.7
MEDIUMCVE-2022-43673
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database.... Read more
- EPSS Score: %0.04
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2022-43308
INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.... Read more
- EPSS Score: %0.03
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-43140
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via in... Read more
Affected Products : kkfileview- EPSS Score: %75.79
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-43138
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.10
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-42982
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can ... Read more
Affected Products : bkg_professional_ntripcaster- EPSS Score: %0.20
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2022-42904
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %13.03
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-3600
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.... Read more
- EPSS Score: %0.54
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-3336
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack... Read more
Affected Products : event_monster- EPSS Score: %0.17
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-38871
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.... Read more
Affected Products : free5gc- EPSS Score: %0.08
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20427
In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025