Latest CVE Feed
-
9.8
CRITICALCVE-2018-1475
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.... Read more
Affected Products : bigfix_platform- EPSS Score: %0.38
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-25068
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/Fil... Read more
Affected Products : globalpom-utils- EPSS Score: %0.05
- Published: Jan. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42897
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.... Read more
Affected Products : feminer_wms- EPSS Score: %7.06
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19006
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.... Read more
Affected Products : freepbx- EPSS Score: %1.86
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19033
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.... Read more
Affected Products : jcms- EPSS Score: %0.91
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43086
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() i... Read more
Affected Products : adaptive_scalable_texture_compression_encoder- EPSS Score: %0.38
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23355
This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization... Read more
Affected Products : ps-kill- EPSS Score: %1.43
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24019
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain tha... Read more
Affected Products : forticlient_endpoint_management_server- EPSS Score: %15.19
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24037
A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the applicatio... Read more
Affected Products : hermes- EPSS Score: %0.54
- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7237
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69... Read more
Affected Products : spiceworks- EPSS Score: %28.74
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-43484
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.... Read more
Affected Products : simple_client_management_system- EPSS Score: %12.71
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43571
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.... Read more
Affected Products : ecdsa-node- EPSS Score: %0.22
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19169
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.... Read more
- EPSS Score: %1.06
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4381
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This make... Read more
Affected Products : ulisting- EPSS Score: %0.37
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6792
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability... Read more
Affected Products : android- EPSS Score: %2.77
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-1628
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.... Read more
Affected Products : mule- EPSS Score: %0.35
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15145
Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.... Read more
Affected Products : openemr- EPSS Score: %0.02
- Published: Aug. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla... Read more
Affected Products : video_gallery- EPSS Score: %6.45
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2021-24666
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both param... Read more
Affected Products : podlove_podcast_publisher- EPSS Score: %77.91
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44350
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.... Read more
Affected Products : thinkphp- EPSS Score: %1.03
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024