Latest CVE Feed
-
9.8
CRITICALCVE-2017-7237
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69... Read more
Affected Products : spiceworks- EPSS Score: %28.74
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-43484
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.... Read more
Affected Products : simple_client_management_system- EPSS Score: %12.71
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43571
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.... Read more
Affected Products : ecdsa-node- EPSS Score: %0.22
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19169
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.... Read more
- EPSS Score: %1.06
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4381
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This make... Read more
Affected Products : ulisting- EPSS Score: %0.37
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6792
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability... Read more
Affected Products : android- EPSS Score: %2.77
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-1628
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.... Read more
Affected Products : mule- EPSS Score: %0.35
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15145
Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.... Read more
Affected Products : openemr- EPSS Score: %0.02
- Published: Aug. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla... Read more
Affected Products : video_gallery- EPSS Score: %6.45
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2021-24666
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both param... Read more
Affected Products : podlove_podcast_publisher- EPSS Score: %77.91
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44350
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.... Read more
Affected Products : thinkphp- EPSS Score: %1.03
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44352
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.... Read more
- EPSS Score: %1.22
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24915
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unaut... Read more
Affected Products : contest_gallery- EPSS Score: %74.56
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2008-3604
SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.... Read more
Affected Products : zeebuddy- EPSS Score: %1.42
- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2016-1000217
Zotpress plugin for WordPress SQLi in zp_get_account()... Read more
- EPSS Score: %11.40
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-1010259
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt.... Read more
- EPSS Score: %0.37
- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %49.26
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20418
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.... Read more
- EPSS Score: %0.14
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45692
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.... Read more
Affected Products : messagepack-rs- EPSS Score: %0.31
- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-7098
OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.... Read more
Affected Products : openconnect- EPSS Score: %0.68
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024