Latest CVE Feed
-
9.8
CRITICALCVE-2024-50716
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component.... Read more
Affected Products : smart_agent- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
5.3
MEDIUMCVE-2024-45440
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.... Read more
Affected Products : drupal- Published: Aug. 29, 2024
- Modified: Apr. 21, 2025
-
6.9
MEDIUMCVE-2024-0545
A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://evil.com leads to... Read more
Affected Products : rise_ultimate_project_manager- Published: Jan. 15, 2024
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-46702
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
6.5
MEDIUMCVE-2022-46695
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that f... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-46694
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-46693
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary co... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-46692
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2022-46691
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may ... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2022-46393
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_C... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.3
MEDIUMCVE-2022-46392
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.2
HIGHCVE-2022-46127
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product.... Read more
Affected Products : helmet_store_showroom_site- Published: Dec. 14, 2022
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2022-45969
Alist v3.4.0 is vulnerable to Directory Traversal,... Read more
Affected Products : alist- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-45338
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.... Read more
Affected Products : exact_synergy- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2022-45033
A cross-site scripting (XSS) vulnerability in Expense Tracker 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat text field.... Read more
Affected Products : expense_tracker- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2022-44236
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.... Read more
Affected Products : voip_simplicity_asg- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
6.1
MEDIUMCVE-2022-44235
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : voip_simplicity_asg- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2022-42867
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42866
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42865
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025