Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2022-45475

    Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control. ... Read more

    Affected Products : tiny_file_manager
    • EPSS Score: %0.17
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 7.5

    HIGH
    CVE-2022-45470

    missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.... Read more

    Affected Products : hama
    • EPSS Score: %0.24
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 8.8

    HIGH
    CVE-2022-45461

    The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.... Read more

    Affected Products : linux_kernel netbackup unix
    • EPSS Score: %0.47
    • Published: Nov. 17, 2022
    • Modified: Apr. 29, 2025
  • 6.1

    MEDIUM
    CVE-2022-45225

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_ti... Read more

    Affected Products : book_store_management_system
    • EPSS Score: %0.10
    • Published: Nov. 25, 2022
    • Modified: Apr. 29, 2025
  • 4.8

    MEDIUM
    CVE-2022-45017

    A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.... Read more

    Affected Products : wbce_cms
    • EPSS Score: %0.12
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 4.8

    MEDIUM
    CVE-2022-45016

    A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.... Read more

    Affected Products : wbce_cms
    • EPSS Score: %0.12
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44401

    Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.... Read more

    • EPSS Score: %0.10
    • Published: Nov. 28, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44183

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.53
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44180

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44178

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44177

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44176

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44175

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-44174

    Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 4.9

    MEDIUM
    CVE-2022-43709

    MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.... Read more

    Affected Products : mybb
    • EPSS Score: %0.06
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 5.5

    MEDIUM
    CVE-2022-40954

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG ... Read more

    • EPSS Score: %0.60
    • Published: Nov. 22, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2022-3980

    An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.... Read more

    Affected Products : mobile
    • EPSS Score: %88.02
    • Published: Nov. 16, 2022
    • Modified: Apr. 29, 2025
  • 7.5

    HIGH
    CVE-2022-36785

    D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 "login.asp" A. The window.location.href = http://192.168.1.1/setupWizard.asp" http://192.168.1.1... Read more

    • EPSS Score: %0.17
    • Published: Nov. 17, 2022
    • Modified: Apr. 29, 2025
  • 7.5

    HIGH
    CVE-2022-24999

    qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker ca... Read more

    Affected Products : debian_linux qs express
    • EPSS Score: %3.42
    • Published: Nov. 26, 2022
    • Modified: Apr. 29, 2025
  • 7.5

    HIGH
    CVE-2022-24190

    The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users pict... Read more

    Affected Products : ourphoto
    • EPSS Score: %0.08
    • Published: Nov. 28, 2022
    • Modified: Apr. 29, 2025
Showing 20 of 291737 Results