Latest CVE Feed
-
9.8
CRITICALCVE-2022-45476
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload. ... Read more
Affected Products : tiny_file_manager- EPSS Score: %0.39
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
6.5
MEDIUMCVE-2022-45475
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control. ... Read more
Affected Products : tiny_file_manager- EPSS Score: %0.17
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-45470
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.... Read more
Affected Products : hama- EPSS Score: %0.24
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
8.8
HIGHCVE-2022-45461
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.... Read more
- EPSS Score: %0.47
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
6.1
MEDIUMCVE-2022-45225
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_ti... Read more
Affected Products : book_store_management_system- EPSS Score: %0.10
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45017
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.... Read more
Affected Products : wbce_cms- EPSS Score: %0.12
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45016
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.... Read more
Affected Products : wbce_cms- EPSS Score: %0.12
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44401
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.... Read more
Affected Products : online_tours_\&_travels_management_system- EPSS Score: %0.10
- Published: Nov. 28, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44183
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.... Read more
- EPSS Score: %0.53
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44180
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44178
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44177
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44176
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44175
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44174
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.9
MEDIUMCVE-2022-43709
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.... Read more
Affected Products : mybb- EPSS Score: %0.06
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
5.5
MEDIUMCVE-2022-40954
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG ... Read more
- EPSS Score: %0.60
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-3980
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.... Read more
Affected Products : mobile- EPSS Score: %88.02
- Published: Nov. 16, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-36785
D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 "login.asp" A. The window.location.href = http://192.168.1.1/setupWizard.asp" http://192.168.1.1... Read more
- EPSS Score: %0.17
- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
7.5
HIGHCVE-2022-24999
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker ca... Read more
- EPSS Score: %3.42
- Published: Nov. 26, 2022
- Modified: Apr. 29, 2025