Latest CVE Feed
-
9.8
CRITICALCVE-2020-26542
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to com... Read more
Affected Products : percona_server- EPSS Score: %0.70
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18387
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, ... Read more
Affected Products : hotel_and_lodge_management_system- EPSS Score: %0.70
- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6553
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward Open service request is passed to a fixed size buffer, allowing an attacker ... Read more
Affected Products : rslinx- EPSS Score: %5.35
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18623
Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with access rights matching the user who created the dashboard.... Read more
Affected Products : energycap- EPSS Score: %0.47
- Published: Nov. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27488
Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to us... Read more
- EPSS Score: %0.98
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27739
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in ... Read more
Affected Products : webcit- EPSS Score: %2.23
- Published: Oct. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18858
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.... Read more
- EPSS Score: %0.52
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6203
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.... Read more
- EPSS Score: %7.52
- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28074
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.... Read more
Affected Products : online_health_care_system- EPSS Score: %0.84
- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.... Read more
- EPSS Score: %5.65
- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28194
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.... Read more
Affected Products : accel-ppp- EPSS Score: %0.63
- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28269
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : field- EPSS Score: %2.63
- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28274
Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : deepref- EPSS Score: %1.78
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19750
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.... Read more
Affected Products : msos- EPSS Score: %0.35
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28864
Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspecified impact via a long file name.... Read more
Affected Products : winscp- EPSS Score: %0.62
- Published: Nov. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29006
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.... Read more
Affected Products : misp- EPSS Score: %0.36
- Published: Nov. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29595
PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000031aa.... Read more
Affected Products : photo_studio_2021- EPSS Score: %0.43
- Published: Dec. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-26168
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authent... Read more
- EPSS Score: %0.87
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-4576
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows... Read more
- EPSS Score: %2.35
- Published: May. 23, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-8979
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.... Read more
Affected Products : kohana- EPSS Score: %8.41
- Published: Feb. 21, 2019
- Modified: Nov. 21, 2024