Latest CVE Feed
-
8.2
HIGHCVE-2025-30287
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage ... Read more
Affected Products : coldfusion- Published: Apr. 08, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-25234
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.... Read more
Affected Products : unified_access_gateway- Published: Apr. 17, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
8.2
HIGHCVE-2025-30288
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass secur... Read more
Affected Products : coldfusion- Published: Apr. 08, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-30291
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged attacker with local access could leverage this vulnerability to gain access to ... Read more
Affected Products : coldfusion- Published: Apr. 08, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-29015
Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.7
MEDIUMCVE-2022-42830
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 21, 2025
-
9.6
CRITICALCVE-2022-40004
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.... Read more
Affected Products : thingsboard- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2025-0436
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-57760
JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.... Read more
Affected Products : jeewms- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-0434
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0435
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
2.5
LOWCVE-2025-32408
In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.... Read more
Affected Products : iam- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2022-42842
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42841
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Processing a maliciously crafted package may lead to arbitrary code execution.... Read more
Affected Products : macos- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42840
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2022-42837
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
6.4
MEDIUMCVE-2022-42832
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 21, 2025
-
6.4
MEDIUMCVE-2022-42831
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42821
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.... Read more
Affected Products : macos- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42805
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025