Latest CVE Feed
-
9.8
CRITICALCVE-2020-8638
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.... Read more
Affected Products : testlink- EPSS Score: %0.26
- Published: Apr. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0086
In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arbitrary code execution if IntSan were not enabled, which it is by default. No additional execution privileges are required. User interac... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Mar. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0333
In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A... Read more
Affected Products : android- EPSS Score: %0.65
- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15321
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.... Read more
- EPSS Score: %0.51
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17206
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.... Read more
Affected Products : redis_wrapper- EPSS Score: %0.74
- Published: Oct. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14699
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.... Read more
- EPSS Score: %69.48
- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12800
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- EPSS Score: %92.20
- Published: Jun. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15851
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible ... Read more
Affected Products : backup_\&_replication_transporter- EPSS Score: %1.04
- Published: Sep. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10008
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the ... Read more
Affected Products : weipdcrm- EPSS Score: %0.05
- Published: Jan. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10015
A vulnerability, which was classified as critical, has been found in glidernet ogn-live. This issue affects some unknown processing. The manipulation leads to sql injection. The patch is named bc0f19965f760587645583b7624d66a260946e01. It is recommended to... Read more
Affected Products : ogn-live- EPSS Score: %0.04
- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14708
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.... Read more
- EPSS Score: %0.48
- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22801
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions. Affected Product: ConneXium Network Manager Software (All Versions)... Read more
Affected Products : connexium_network_manager- EPSS Score: %0.84
- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1475
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.... Read more
Affected Products : bigfix_platform- EPSS Score: %0.38
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-25068
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/Fil... Read more
Affected Products : globalpom-utils- EPSS Score: %0.05
- Published: Jan. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42897
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.... Read more
Affected Products : feminer_wms- EPSS Score: %7.06
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19006
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.... Read more
Affected Products : freepbx- EPSS Score: %1.86
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19033
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.... Read more
Affected Products : jcms- EPSS Score: %0.91
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43086
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() i... Read more
Affected Products : adaptive_scalable_texture_compression_encoder- EPSS Score: %0.38
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23355
This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization... Read more
Affected Products : ps-kill- EPSS Score: %1.43
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24019
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain tha... Read more
Affected Products : forticlient_endpoint_management_server- EPSS Score: %15.19
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024