Latest CVE Feed
-
7.5
HIGHCVE-2022-20685
A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing... Read more
- Published: Nov. 15, 2024
- Modified: Jun. 24, 2025
-
6.1
MEDIUMCVE-2022-20663
A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.... Read more
Affected Products : secure_network_analytics- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
6.1
MEDIUMCVE-2022-20657
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because t... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
6.5
MEDIUMCVE-2022-20656
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid ... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
8.8
HIGHCVE-2022-20655
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an affect... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2022-20654
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability is due to insufficient va... Read more
Affected Products : webex_meetings- Published: Nov. 15, 2024
- Modified: Aug. 07, 2025
-
6.5
MEDIUMCVE-2022-20652
A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system.... Read more
Affected Products : secure_workload- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
8.1
HIGHCVE-2022-20649
A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container. This vulner... Read more
Affected Products : redundancy_configuration_manager- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
5.3
MEDIUMCVE-2022-20648
A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debug actions that could result in the disclosure of confidential information that should be restricted. This... Read more
Affected Products : redundancy_configuration_manager- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2022-20634
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP r... Read more
Affected Products : enterprise_chat_and_email- Published: Nov. 15, 2024
- Modified: Aug. 11, 2025
-
6.1
MEDIUMCVE-2022-20631
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based managem... Read more
Affected Products : enterprise_chat_and_email- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
5.5
MEDIUMCVE-2022-20626
A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. The attacker would require valid c... Read more
Affected Products : prime_access_registrar- Published: Nov. 15, 2024
- Modified: Aug. 07, 2025
-
7.3
HIGHCVE-2024-50986
An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.... Read more
Affected Products : clementine- Published: Nov. 15, 2024
- Modified: Jul. 07, 2025
-
6.1
MEDIUMCVE-2024-48068
A cross-site scripting (XSS) vulnerability in Shenzhen Landray Software Co.,LTD Landray EKP v16 and earlier allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2024-43189
IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information u... Read more
Affected Products : concert- Published: Nov. 15, 2024
- Modified: Jul. 18, 2025
-
6.1
MEDIUMCVE-2024-41785
IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : concert- Published: Nov. 15, 2024
- Modified: Jul. 18, 2025
-
5.3
MEDIUMCVE-2024-20373
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP polling of an aff... Read more
Affected Products : ios_xe_sd-wan- Published: Nov. 15, 2024
- Modified: Aug. 01, 2025
-
6.9
MEDIUMCVE-2024-11243
A vulnerability classified as problematic has been found in code-projects Online Shop Store 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument m2 with the input <svg%20onload=alert(document.cookie)> leads to cross ... Read more
- Published: Nov. 15, 2024
- Modified: Dec. 10, 2024
-
7.2
HIGHCVE-2024-11242
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ad_list.php?action=pass of the component Keyword Filtering. The manipulation of the argument keyword leads to s... Read more
Affected Products : zzcms- Published: Nov. 15, 2024
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2024-11241
A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file reset.php. The manipulation of the argument e leads to sql injection. The attack can b... Read more
Affected Products : job_recruitment- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024