Latest CVE Feed
-
9.8
CRITICALCVE-2021-40881
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.... Read more
Affected Products : publiccms- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6485
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap ... Read more
- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41080
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.... Read more
Affected Products : manageengine_network_configuration_manager- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-52723
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.... Read more
- Published: Nov. 22, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2004-0772
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-40663
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').... Read more
Affected Products : deep.assign- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-52606
SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request.... Read more
- Published: Feb. 11, 2025
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2021-40617
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.... Read more
Affected Products : opensis- Published: Oct. 11, 2021
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2021-40589
ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fileheader.bfOffBits.... Read more
Affected Products : zangband-data- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40612
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.... Read more
Affected Products : open-audit- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40540
ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests.... Read more
Affected Products : ulfius- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40506
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any softw... Read more
- Published: Apr. 18, 2023
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2021-40507
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any... Read more
- Published: Apr. 18, 2023
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2021-33719
A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Specially crafted ... Read more
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14061
Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.... Read more
Affected Products : libidn2- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.... Read more
- Published: Nov. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2021-40409
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided throug... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40417
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate th... Read more
Affected Products : davinci_resolve- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40373
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.... Read more
Affected Products : playsms- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40323
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024