Latest CVE Feed
-
9.8
CRITICALCVE-2021-22679
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versio... Read more
Affected Products : cc3100_software_development_kit cc3200_software_development_kit simplelink_cc13x0_software_development_kit simplelink_cc13x2_software_development_kit simplelink_cc26xx_software_development_kit simplelink_cc32xx_software_development_kit simplelink_msp432e4_software_development_kit- EPSS Score: %0.70
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5923
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.... Read more
Affected Products : color_laserjet_cm4540_mfp_firmware color_laserjet_cp5525_firmware color_laserjet_enterprise_flow_mfp_m681f_firmware color_laserjet_enterprise_flow_mfp_m681z_firmware color_laserjet_enterprise_flow_mfp_m682z_firmware color_laserjet_enterprise_m552_firmware color_laserjet_enterprise_m553_firmware color_laserjet_enterprise_m651_firmware color_laserjet_enterprise_m652n_firmware color_laserjet_enterprise_m652dn_firmware +266 more products- EPSS Score: %1.54
- Published: Mar. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6024
SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.... Read more
Affected Products : project_log- EPSS Score: %2.64
- Published: Feb. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-18717
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.... Read more
Affected Products : zzzphp- EPSS Score: %7.21
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-1925
SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote authenticated users to execute arbitrar... Read more
Affected Products : koha- EPSS Score: %2.52
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37222
Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.... Read more
Affected Products : rcdcap- EPSS Score: %0.88
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-3773
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.... Read more
- EPSS Score: %0.31
- Published: Jan. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37421
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.... Read more
Affected Products : manageengine_adselfservice_plus- EPSS Score: %8.91
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37422
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.... Read more
Affected Products : manageengine_adselfservice_plus- EPSS Score: %36.35
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29353
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.... Read more
Affected Products : graphql-upload- EPSS Score: %0.97
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29383
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.... Read more
- EPSS Score: %78.81
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37580
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0... Read more
Affected Products : shenyu- EPSS Score: %93.99
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42637
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.... Read more
Affected Products : web_stack- EPSS Score: %1.46
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18530
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.... Read more
Affected Products : thinkphp- EPSS Score: %0.26
- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-42837
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary p... Read more
Affected Products : data_catalog- EPSS Score: %0.48
- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37059
There is a Weaknesses Introduced During Design... Read more
Affected Products : harmonyos- EPSS Score: %0.24
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-18890
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.... Read more
Affected Products : puppycms- EPSS Score: %0.64
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37919
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %37.38
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37927
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.... Read more
Affected Products : manageengine_admanager_plus- EPSS Score: %0.32
- Published: Sep. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43118
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious ... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- EPSS Score: %46.15
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024