Latest CVE Feed
-
9.8
CRITICALCVE-2020-36199
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.... Read more
Affected Products : tinycheck- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8799
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames. To exploit this vulnerability, a virtual iRODS pathname tha... Read more
Affected Products : irods- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-22755
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabiliti... Read more
- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2161
Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . ... Read more
Affected Products :- Published: Mar. 21, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000653
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.... Read more
Affected Products : zzcms- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.... Read more
Affected Products : online_exam_test_application_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-21234
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.... Read more
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43882
Microsoft Defender for IoT Remote Code Execution Vulnerability... Read more
Affected Products : defender_for_iot- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-16975
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input va... Read more
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27983
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.... Read more
Affected Products : maxsite_cms- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.... Read more
Affected Products : multireligion_responsive_matrimonial- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-18696
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or MSM8996 chipsets) software. RKP allows memory corruption. The Samsung ID is SVE-2016-7897 (January 2017).... Read more
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12193
H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.... Read more
Affected Products : h3cloud_os- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17137
Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions.... Read more
Affected Products : next- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12698
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.... Read more
Affected Products : webaccess- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12471
The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to check for out-of-bounds conditions, which triggers an invalid read in the hexdump function.... Read more
Affected Products : ccn-lite- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19307
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.... Read more
Affected Products : mongoose- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15823
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.... Read more
Affected Products : wps_hide_login- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16165
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.... Read more
- Published: Jul. 30, 2020
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-50434
emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The im... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024