Latest CVE Feed
-
7.5
HIGHCVE-2022-43140
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via in... Read more
Affected Products : kkfileview- EPSS Score: %75.79
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-43138
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.10
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-42982
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can ... Read more
Affected Products : bkg_professional_ntripcaster- EPSS Score: %0.20
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2022-42904
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %13.03
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-3600
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.... Read more
- EPSS Score: %0.54
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-3336
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack... Read more
Affected Products : event_monster- EPSS Score: %0.17
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-38871
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.... Read more
Affected Products : free5gc- EPSS Score: %0.08
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20427
In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-24649
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having ac... Read more
Affected Products : wp_user_frontend- EPSS Score: %0.27
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
5.8
MEDIUMCVE-2024-20291
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked throug... Read more
Affected Products : nx-os nexus_3048 nexus_31108pc-v nexus_31108tc-v nexus_31128pq nexus_3132c-z nexus_3132q-v nexus_3132q-xl nexus_3164q nexus_3172pq +71 more products- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3457
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-21682
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira... Read more
Affected Products : assets_discovery_data_center- Published: Feb. 20, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3458
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3472
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-25431
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.... Read more
- Published: Feb. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-29743
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45427
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more
- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3341
A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is p... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3342
A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3343
A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection.... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection