Latest CVE Feed
-
7.8
HIGHCVE-2022-39097
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39096
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39095
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39094
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39093
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39092
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39091
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39090
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-25630
An authenticated user can embed malicious content with XSS into the admin group policy page.... Read more
Affected Products : messaging_gateway- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-25629
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).... Read more
Affected Products : messaging_gateway- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-1540
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.... Read more
Affected Products : postmagthemes_demo_import- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2020-6627
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a che... Read more
Affected Products : stcg2000300_firmware stcg3000300_firmware stcg4000300_firmware stcg2000300 stcg3000300 stcg4000300- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
9.1
CRITICALCVE-2024-35049
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.... Read more
Affected Products : surveyking- Published: May. 14, 2024
- Modified: Apr. 23, 2025
-
8.8
HIGHCVE-2024-35050
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.... Read more
Affected Products : surveyking- Published: May. 14, 2024
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2025-3174
A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to... Read more
- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-44817
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.... Read more
Affected Products : zzcms- Published: Sep. 04, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-44818
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.... Read more
Affected Products : zzcms- Published: Sep. 04, 2024
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2024-44821
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly ... Read more
Affected Products : zzcms- Published: Sep. 04, 2024
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2024-11242
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ad_list.php?action=pass of the component Keyword Filtering. The manipulation of the argument keyword leads to s... Read more
Affected Products : zzcms- Published: Nov. 15, 2024
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2025-1949
A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_S... Read more
Affected Products : zzcms- Published: Mar. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting