Latest CVE Feed
-
9.8
CRITICAL- EPSS Score: %1.60
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44804
D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.... Read more
- EPSS Score: %0.42
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICAL- EPSS Score: %1.15
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICAL- EPSS Score: %1.60
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44172
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44171
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-44169
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.... Read more
- EPSS Score: %0.10
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
7.2
HIGHCVE-2022-43179
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.... Read more
Affected Products : online_leave_management_system- EPSS Score: %0.09
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
9.6
CRITICALCVE-2022-43143
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.... Read more
Affected Products : beekeeper-studio- EPSS Score: %0.38
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
5.4
MEDIUMCVE-2022-43117
Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.... Read more
Affected Products : password_storage_application- EPSS Score: %1.40
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-42891
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the a... Read more
Affected Products : syngo_dynamics_cardiovascular_imaging_and_information_system- EPSS Score: %0.16
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-42734
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the a... Read more
Affected Products : syngo_dynamics_cardiovascular_imaging_and_information_system- EPSS Score: %0.16
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-42733
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible... Read more
Affected Products : syngo_dynamics_cardiovascular_imaging_and_information_system- EPSS Score: %0.22
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-42096
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.... Read more
- EPSS Score: %5.79
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-40470
Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.... Read more
Affected Products : blood_donor_management_system- EPSS Score: %1.40
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
6.1
MEDIUMCVE-2022-3561
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.... Read more
Affected Products : librenms- EPSS Score: %0.07
- Published: Nov. 20, 2022
- Modified: Apr. 29, 2025
-
7.8
HIGHCVE-2022-37197
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.... Read more
Affected Products : iotransfer- EPSS Score: %0.12
- Published: Nov. 18, 2022
- Modified: Apr. 29, 2025
-
9.9
CRITICALCVE-2022-36786
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the ro... Read more
- EPSS Score: %0.09
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
9.9
CRITICAL- EPSS Score: %0.09
- Published: Nov. 18, 2022
- Modified: Apr. 29, 2025
-
6.1
MEDIUMCVE-2021-31739
The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attributes when returned by the server.SEPPmail 11.1.10 allows XSS via a recipient address.... Read more
Affected Products : seppmail- EPSS Score: %0.10
- Published: Nov. 18, 2022
- Modified: Apr. 29, 2025