Latest CVE Feed
-
3.8
LOWCVE-2024-31144
For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-overview Xapi contains functionality to backup and restore metadata about Virtual Machines and Storage Repositories (SRs). The metadata ... Read more
Affected Products : xen- Published: Feb. 14, 2025
- Modified: Apr. 26, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-31143
An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling an error path could be ... Read more
Affected Products : xen- Published: Jul. 18, 2024
- Modified: Apr. 26, 2025
-
6.5
MEDIUMCVE-2023-28746
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Mar. 14, 2024
- Modified: Apr. 26, 2025
-
7.4
HIGHCVE-2025-22228
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.... Read more
Affected Products : spring_security- Published: Mar. 20, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2024-9287
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source v... Read more
Affected Products : python- Published: Oct. 22, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-6096
In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.... Read more
Affected Products : telerik_reporting- Published: Jul. 24, 2024
- Modified: Apr. 25, 2025
-
5.9
MEDIUMCVE-2024-10846
The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from vers... Read more
Affected Products :- Published: Jan. 23, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2018-5733
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8,... Read more
- EPSS Score: %25.82
- Published: Jan. 16, 2019
- Modified: Apr. 25, 2025
-
4.9
MEDIUMCVE-2022-45535
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- EPSS Score: %0.09
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
4.9
MEDIUMCVE-2022-45529
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- EPSS Score: %0.09
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-45331
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- EPSS Score: %0.08
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-45330
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- EPSS Score: %0.08
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can proces... Read more
- EPSS Score: %5.08
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44252
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.... Read more
- EPSS Score: %1.39
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44251
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.... Read more
- EPSS Score: %1.39
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44250
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.... Read more
- EPSS Score: %1.39
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44249
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.... Read more
- EPSS Score: %1.39
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44139
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.... Read more
Affected Products : apartment_visitors_management_system- EPSS Score: %0.08
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44120
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.... Read more
Affected Products : dedecmsv6- EPSS Score: %0.07
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
4.8
MEDIUMCVE-2022-42985
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).... Read more
Affected Products : scratch_login- EPSS Score: %0.14
- Published: Nov. 17, 2022
- Modified: Apr. 25, 2025