Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.5
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
Published Sep 25, 2022 · Updated May 22, 2025
Medium · CVSS 6.1
Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a user’s screen.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.1
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.1
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted image may result in disclosure of process memory.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.9
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak sensitive information.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.1
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 8.8
Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 8.8
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
Medium · CVSS 4.3
The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Published Sep 26, 2022 · Updated May 22, 2025
Medium · CVSS 5.4
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 7.5
The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 7.8
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.4
The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 7.8
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. An app may be able to gain elevated privileges.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.5
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.
Published Sep 24, 2022 · Updated May 22, 2025
High · CVSS 7.8
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
Published Sep 25, 2022 · Updated May 22, 2025
Medium · CVSS 6.1
The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app.
Published Sep 26, 2022 · Updated May 22, 2025
Critical · CVSS 10
This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 4.8
The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Published Sep 26, 2022 · Updated May 22, 2025
Medium · CVSS 4.8
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Published Sep 26, 2022 · Updated May 22, 2025
Medium · CVSS 4.8
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.
Published Sep 27, 2022 · Updated May 22, 2025
High · CVSS 8.8
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 7.4
Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials.
Published Sep 27, 2022 · Updated May 22, 2025
Medium · CVSS 6.5
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
Published Sep 27, 2022 · Updated May 22, 2025
High · CVSS 8.8
Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 8.8
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Published Sep 27, 2022 · Updated May 22, 2025
Medium · CVSS 6.5
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.
Published Sep 26, 2022 · Updated May 22, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php.
Published Sep 27, 2022 · Updated May 22, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php.
Published Sep 27, 2022 · Updated May 22, 2025
High · CVSS 8.8
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.3
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 5.3
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Published Sep 26, 2022 · Updated May 21, 2025
Medium · CVSS 5.7
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Published Sep 26, 2022 · Updated May 21, 2025
High · CVSS 7.8
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
Published Sep 25, 2022 · Updated May 21, 2025