Latest CVE Feed
-
8.8
HIGHCVE-2022-3769
The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as contributor... Read more
Affected Products : owm_weather- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-3751
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.... Read more
Affected Products : owncast- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
7.2
HIGHCVE-2022-3689
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users... Read more
Affected Products : html_forms- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
6.1
MEDIUMCVE-2022-36433
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.... Read more
Affected Products : amasty_blog_pro- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
4.8
MEDIUMCVE-2022-36137
ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.... Read more
Affected Products : churchcrm- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
4.8
MEDIUMCVE-2022-36136
ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input Deposit Comment.... Read more
Affected Products : churchcrm- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-23746
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.... Read more
Affected Products : ssl_network_extender- Published: Nov. 30, 2022
- Modified: Apr. 25, 2025
-
6.3
MEDIUMCVE-2022-22984
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin befo... Read more
- Published: Nov. 30, 2022
- Modified: Apr. 25, 2025
-
6.1
MEDIUMCVE-2021-31740
SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (XSS).... Read more
Affected Products : seppmail- Published: Nov. 30, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2021-25059
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of th... Read more
Affected Products : download_plugin- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
6.1
MEDIUMCVE-2020-21219
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 25, 2025
-
7.8
HIGHCVE-2024-0406
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files ... Read more
- Published: Apr. 06, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-3204
A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulation leads to heap-based buffer overfl... Read more
- Published: Apr. 02, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-3203
A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible ... Read more
Affected Products : c-blosc2- Published: Apr. 02, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-3207
A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file src/Simd/SimdMemoryStream.h. The manipulation leads to heap-based buffer overflow. The exploit ha... Read more
Affected Products : simd- Published: Apr. 02, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-3209
A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. T... Read more
- Published: Apr. 02, 2024
- Modified: Apr. 25, 2025
-
7.2
HIGHCVE-2024-3227
A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/theme_set/save_image.php of the component Backend. The manipulation of the argument i... Read more
- Published: Apr. 03, 2024
- Modified: Apr. 25, 2025
-
7.1
HIGHCVE-2024-49672
Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn Google Docs RSVP allows Stored XSS.This issue affects Google Docs RSVP: from n/a through 2.0.1.... Read more
- Published: Oct. 29, 2024
- Modified: Apr. 25, 2025
-
0.0
NACVE-2025-22126
In the Linux kernel, the following vulnerability has been resolved: md: fix mddev uaf while iterating all_mddevs list While iterating all_mddevs list from md_notify_reboot() and md_exit(), list_for_each_entry_safe is used, and this can race with deletin... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-22077
In the Linux kernel, the following vulnerability has been resolved: Revert "smb: client: fix TCP timers deadlock after rmmod" This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801. Commit e9f2517a3e18 ("smb: client: fix TCP timers deadlock after... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption