Latest CVE Feed
-
6.5
MEDIUMCVE-2022-3926
The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID... Read more
- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2022-3711
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.... Read more
- Published: Dec. 01, 2022
- Modified: Apr. 23, 2025
-
8.1
HIGHCVE-2022-3262
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and av... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
4.8
MEDIUMCVE-2022-3260
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-3249
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks... Read more
Affected Products : wp_csv_exporter- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
6.8
MEDIUMCVE-2022-39044
Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and ea... Read more
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
6.5
MEDIUMCVE-2022-38765
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.... Read more
Affected Products : vitrea_view- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
6.5
MEDIUMCVE-2022-38599
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.... Read more
Affected Products : teleport- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
8.1
HIGHCVE-2022-37918
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive inf... Read more
Affected Products : airwave- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
8.1
HIGHCVE-2022-37917
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive inf... Read more
Affected Products : airwave- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
8.1
HIGHCVE-2022-37916
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive inf... Read more
Affected Products : airwave- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2022-33186
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabl... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2020-36565
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.... Read more
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2019-16905
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution beca... Read more
- Published: Oct. 09, 2019
- Modified: Apr. 23, 2025
-
10.0
CRITICALCVE-2015-8104
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.... Read more
- Published: Nov. 16, 2015
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2009-3791
Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors.... Read more
Affected Products : flash_media_server- Published: Dec. 21, 2009
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2009-2541
The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.... Read more
Affected Products : playstation_3- Published: Jul. 20, 2009
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2008-2991
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.... Read more
Affected Products : robohelp_server- Published: Jul. 09, 2008
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2008-0642
Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote attackers to inject arbitrary web script or HTML via unspeci... Read more
Affected Products : robohelp- Published: Feb. 15, 2008
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2001-0827
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.... Read more
Affected Products : ceberus_ftp_server- Published: Dec. 06, 2001
- Modified: Apr. 23, 2025