Latest CVE Feed
-
9.8
CRITICALCVE-2022-25688
Memory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wea... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +289 more products- EPSS Score: %0.19
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5432
The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible f... Read more
Affected Products : lifeline_donation- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.43
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38584
In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication. ... Read more
Affected Products : cmt3071_firmware cmt3072_firmware cmt3090_firmware cmt3103_firmware cmt3151_firmware cmt-hdm_firmware cmt-fhd_firmware cmt3071 cmt3072 cmt3090 +4 more products- EPSS Score: %0.06
- Published: Oct. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36657
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.... Read more
Affected Products : metadefender_kiosk- EPSS Score: %0.41
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29594
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.... Read more
Affected Products : rocket.chat- EPSS Score: %0.40
- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6328
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.... Read more
- EPSS Score: %71.73
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25809
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in th... Read more
- EPSS Score: %7.45
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46977
TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.... Read more
- EPSS Score: %11.13
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23739
An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.... Read more
- EPSS Score: %30.37
- Published: Jan. 28, 2024
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2024-3098
A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of inp... Read more
Affected Products : llamaindex- Published: Apr. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10620
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such... Read more
- EPSS Score: %7.69
- Published: Jul. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23813
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute cod... Read more
Affected Products : polarion_alm- EPSS Score: %0.14
- Published: Feb. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-3746
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to ga... Read more
- EPSS Score: %0.99
- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10211
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow ... Read more
- EPSS Score: %1.68
- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12568
Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387... Read more
Affected Products : open_tftp_server- EPSS Score: %2.74
- Published: Dec. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0852
Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitra... Read more
Affected Products : mf1127c_firmware mf641cw_firmware mf642cdw_firmware mf644cdw_firmware mf741cdw_firmware mf743cdw_firmware mf745cdw_firmware mf746cdw_firmware lbp1127c_firmware lbp622cdw_firmware +80 more products- EPSS Score: %0.24
- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-47204
Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.... Read more
Affected Products : transmute-core- EPSS Score: %0.14
- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24303
SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModu... Read more
Affected Products : gift_wrapping_pro- EPSS Score: %0.29
- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7815
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of... Read more
- EPSS Score: %0.42
- Published: Jul. 10, 2020
- Modified: Nov. 21, 2024