Latest CVE Feed
-
9.8
CRITICALCVE-2022-45969
Alist v3.4.0 is vulnerable to Directory Traversal,... Read more
Affected Products : alist- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-45338
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.... Read more
Affected Products : exact_synergy- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2022-45033
A cross-site scripting (XSS) vulnerability in Expense Tracker 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat text field.... Read more
Affected Products : expense_tracker- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2022-44236
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.... Read more
Affected Products : voip_simplicity_asg- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
6.1
MEDIUMCVE-2022-44235
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : voip_simplicity_asg- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2022-42867
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42866
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42865
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42859
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42854
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1. An app may be able to disclose kernel memory.... Read more
Affected Products : macos- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42853
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.... Read more
Affected Products : macos- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
6.5
MEDIUMCVE-2022-42852
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the dis... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42851
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42850
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42849
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42848
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-42847
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.... Read more
Affected Products : macos- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-42846
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
7.2
HIGHCVE-2022-42845
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary c... Read more
- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2022-40373
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025