Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2022-44384

    An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.... Read more

    Affected Products : rconfig
    • EPSS Score: %0.06
    • Published: Nov. 17, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44262

    ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).... Read more

    Affected Products : ff4j
    • EPSS Score: %2.45
    • Published: Dec. 01, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44001

    An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.... Read more

    Affected Products : backclick
    • EPSS Score: %0.02
    • Published: Nov. 17, 2022
    • Modified: Apr. 29, 2025
  • 8.2

    HIGH
    CVE-2022-43984

    Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does no... Read more

    Affected Products : browsershot
    • EPSS Score: %0.14
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 8.2

    HIGH
    CVE-2022-43983

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the fi... Read more

    Affected Products : browsershot
    • EPSS Score: %0.14
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 6.1

    MEDIUM
    CVE-2022-43708

    MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name... Read more

    Affected Products : mybb
    • EPSS Score: %0.11
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 6.1

    MEDIUM
    CVE-2022-43707

    MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data... Read more

    Affected Products : mybb
    • EPSS Score: %0.10
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 6.1

    MEDIUM
    CVE-2022-43332

    A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.... Read more

    Affected Products : wondercms
    • EPSS Score: %0.24
    • Published: Nov. 17, 2022
    • Modified: Apr. 29, 2025
  • 4.8

    MEDIUM
    CVE-2022-42097

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .... Read more

    Affected Products : backdrop
    • EPSS Score: %0.39
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 4.8

    MEDIUM
    CVE-2022-42094

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.... Read more

    Affected Products : backdrop
    • EPSS Score: %17.37
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 6.5

    MEDIUM
    CVE-2022-41712

    Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.... Read more

    Affected Products : frappe
    • EPSS Score: %0.11
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 8.2

    HIGH
    CVE-2022-41706

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.... Read more

    Affected Products : browsershot
    • EPSS Score: %0.14
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-41705

    Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.... Read more

    Affected Products : badaso
    • EPSS Score: %2.63
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 4.8

    MEDIUM
    CVE-2022-41445

    A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.... Read more

    Affected Products : teacher_record_management_system
    • EPSS Score: %0.96
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 8.8

    HIGH
    CVE-2022-40282

    The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficien... Read more

    • EPSS Score: %1.29
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 7.5

    HIGH
    CVE-2022-38166

    In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service.... Read more

    • EPSS Score: %0.23
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 7.3

    HIGH
    CVE-2022-31694

    InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing... Read more

    Affected Products : installbuilder
    • EPSS Score: %0.07
    • Published: Nov. 18, 2022
    • Modified: Apr. 29, 2025
  • 7.5

    HIGH
    CVE-2022-30256

    An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effect... Read more

    Affected Products : maradns
    • EPSS Score: %0.40
    • Published: Nov. 19, 2022
    • Modified: Apr. 29, 2025
  • 5.4

    MEDIUM
    CVE-2021-37936

    It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search te... Read more

    Affected Products : kibana
    • EPSS Score: %0.96
    • Published: Nov. 18, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2025-2046

    A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The... Read more

    Affected Products : best_employee_management_system
    • Published: Mar. 06, 2025
    • Modified: Apr. 29, 2025
    • Vuln Type: Injection
Showing 20 of 291551 Results