Latest CVE Feed
-
8.8
HIGHCVE-2023-50349
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application. ... Read more
Affected Products : sametime- Published: Feb. 09, 2024
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2023-47459
An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.... Read more
Affected Products : discovery- Published: Jan. 16, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2022-48577
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 17, 2025
-
7.2
HIGHCVE-2022-37780
Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command execution (RCE) vulnerability via the pingAddr parameter of the tracert function.... Read more
Affected Products : fir151b_firmware fir302e_firmware fir300b_firmware fir303b_firmware fir303b fir151b fir302e fir300b- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2022-36661
xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_read(). This vulnerability allows attackers to cause a Denial of Service via unspecified vectors.... Read more
Affected Products : xhyve- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-36660
xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().... Read more
Affected Products : xhyve- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2022-36659
xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnerability allows attackers to cause a Denial of Service via unspecified vectors.... Read more
Affected Products : xhyve- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-36587
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.... Read more
- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-36513
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function edditactionlist.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-36511
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function EditApAdvanceInfo.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2022-36510
H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2022-36509
H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2022-36508
H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetAPInfoById.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2022-36504
H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function Edit_BasicSSID.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2022-32264
sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : freebsd- Published: Sep. 06, 2022
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2022-31414
D-Link DIR-1960 firmware DIR-1960_A1_1.11 was discovered to contain a buffer overflow via srtcat in prog.cgi. This vulnerability allowed attackers to cause a Denial of Service (DoS) via a crafted HTTP request.... Read more
- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2022-30312
The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected compo... Read more
- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2022-23689
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the ... Read more
- Published: Sep. 06, 2022
- Modified: Jun. 17, 2025
-
7.2
HIGHCVE-2022-1807
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.... Read more
- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.... Read more
Affected Products : kirby- Published: Aug. 24, 2022
- Modified: Jun. 17, 2025