Latest CVE Feed
-
5.4
MEDIUMCVE-2023-37529
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerabi... Read more
Affected Products : bigfix_platform- Published: Feb. 29, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2023-37528
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report. ... Read more
Affected Products : bigfix_platform- EPSS Score: %0.28
- Published: Feb. 03, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-37527
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering c... Read more
Affected Products : bigfix_platform- EPSS Score: %0.12
- Published: Feb. 02, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-37523
Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser. ... Read more
Affected Products : bigfix_bare_osd_metal_server_webui- EPSS Score: %0.13
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-34042
The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732:... Read more
- EPSS Score: %0.04
- Published: Feb. 05, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2023-31002
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.... Read more
- EPSS Score: %0.01
- Published: Feb. 07, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2022-40713
An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.... Read more
Affected Products : 1350_optical_management_system- EPSS Score: %0.10
- Published: Sep. 19, 2022
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2022-40712
An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.... Read more
Affected Products : 1350_optical_management_system- EPSS Score: %0.11
- Published: Sep. 19, 2022
- Modified: Jun. 03, 2025
-
7.2
HIGHCVE-2022-38833
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.... Read more
Affected Products : school_activity_updates_with_sms_notification- EPSS Score: %0.09
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
7.2
HIGHCVE-2022-38832
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.... Read more
Affected Products : school_activity_updates_with_sms_notification- EPSS Score: %0.09
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2022-38577
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.... Read more
Affected Products : processmaker- EPSS Score: %20.21
- Published: Sep. 19, 2022
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2022-23767
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining pr... Read more
- EPSS Score: %0.13
- Published: Sep. 19, 2022
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2021-42949
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.... Read more
Affected Products : hoteldruid- EPSS Score: %37.38
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2024-23388
Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of ... Read more
Affected Products : mercari- EPSS Score: %0.18
- Published: Jan. 26, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-38317
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.... Read more
Affected Products : opennds- EPSS Score: %0.24
- Published: Jan. 26, 2024
- Modified: Jun. 03, 2025
-
9.1
CRITICALCVE-2022-39008
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.... Read more
- EPSS Score: %0.20
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2022-39007
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.04
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2022-39001
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.... Read more
- EPSS Score: %0.13
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2022-38887
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.... Read more
Affected Products : d8s-python- EPSS Score: %0.36
- Published: Sep. 19, 2022
- Modified: Jun. 03, 2025
-
7.2
HIGHCVE-2022-38878
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.... Read more
Affected Products : school_activity_updates_with_sms_notification- EPSS Score: %0.09
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025