Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-44790

    Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.... Read more

    Affected Products : email_marketer
    • Published: Dec. 09, 2022
    • Modified: Apr. 23, 2025
  • 8.8

    HIGH
    CVE-2022-44289

    Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.... Read more

    Affected Products : thinkphp
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-43509

    Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.... Read more

    Affected Products : cx-programmer
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-43508

    Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.... Read more

    Affected Products : cx-programmer
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 8.8

    HIGH
    CVE-2022-43464

    Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.... Read more

    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 4.7

    MEDIUM
    CVE-2022-42770

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.... Read more

    Affected Products : android sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 t618 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 3.3

    LOW
    CVE-2022-42769

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more

    Affected Products : android sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 t618 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2022-42458

    Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be alte... Read more

    Affected Products : bingo\!cms
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 5.5

    MEDIUM
    CVE-2022-42329

    Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a dea... Read more

    Affected Products : linux_kernel debian_linux
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 6.2

    MEDIUM
    CVE-2022-42328

    Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a dea... Read more

    Affected Products : linux_kernel debian_linux
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 4.8

    MEDIUM
    CVE-2022-41994

    Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.... Read more

    Affected Products : basercms
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-3907

    The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.... Read more

    Affected Products : clerk.io
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 7.2

    HIGH
    CVE-2022-3858

    The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable b... Read more

    Affected Products : chaty
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-3846

    The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.... Read more

    Affected Products : workreap
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 4.8

    MEDIUM
    CVE-2022-3838

    The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa... Read more

    Affected Products : wpupper_share_buttons
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39099

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39098

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39097

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39096

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39095

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
Showing 20 of 293613 Results