Latest CVE Feed
-
9.8
CRITICALCVE-2024-47311
Missing Authorization vulnerability in Kraft Plugins Wheel of Life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through 1.1.8.... Read more
Affected Products : wheel_of_life- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2021-25912
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : dotty- EPSS Score: %2.95
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25913
Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : set-or-get- EPSS Score: %2.95
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21591
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the ... Read more
Affected Products : junos- EPSS Score: %23.48
- Published: Jan. 12, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2021-25941
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : deep-override- EPSS Score: %2.95
- Published: May. 14, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-39365
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to... Read more
Affected Products : pimcore- EPSS Score: %0.05
- Published: Oct. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8898
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/... Read more
Affected Products : invision_power_board- EPSS Score: %0.56
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-4826
SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisati... Read more
Affected Products :- Published: May. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4825
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.... Read more
Affected Products : cockpit- Published: May. 14, 2024
- Modified: Jun. 27, 2025
-
9.8
CRITICALCVE-2023-2781
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_em... Read more
Affected Products : user_email_verification_for_woocommerce- EPSS Score: %0.36
- Published: Jun. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22319
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. ... Read more
Affected Products : operational_decision_manager- EPSS Score: %90.35
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-27307
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to d... Read more
Affected Products :- Published: Mar. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27847
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.... Read more
Affected Products : xipblog- EPSS Score: %77.06
- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22779
Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.... Read more
Affected Products : serverrpexposer- EPSS Score: %14.33
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0559
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.... Read more
- EPSS Score: %0.33
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22862
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.... Read more
Affected Products : ffmpeg- EPSS Score: %2.00
- Published: Jan. 27, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2024-23058
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.... Read more
- EPSS Score: %3.13
- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23054
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).... Read more
Affected Products : plone_docker_official_image- EPSS Score: %3.91
- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1900
When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stored references. This pre-reservation... Read more
Affected Products : hhvm- EPSS Score: %0.66
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22295
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.... Read more
Affected Products : metinfo- EPSS Score: %0.51
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024