Latest CVE Feed
-
9.8
CRITICALCVE-2024-56431
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.... Read more
- Published: Dec. 25, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-55637
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploi... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2021-38833
SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.... Read more
Affected Products : apartment_visitors_management_system- EPSS Score: %0.52
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38734
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.... Read more
Affected Products : semcms- EPSS Score: %0.34
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-38731
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.... Read more
Affected Products : semcms- EPSS Score: %0.34
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-38687
A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Sur... Read more
- EPSS Score: %0.81
- Published: Dec. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38684
A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Multi... Read more
Affected Products : multimedia_console- EPSS Score: %0.81
- Published: Nov. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38692
A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following ver... Read more
- EPSS Score: %1.21
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38736
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.... Read more
Affected Products : semcms- EPSS Score: %0.34
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-38574
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.... Read more
- EPSS Score: %0.02
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38573
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.... Read more
- EPSS Score: %0.02
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38568
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.... Read more
- EPSS Score: %0.03
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38685
A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR FW 5.1.6... Read more
Affected Products : qvr- EPSS Score: %1.13
- Published: Nov. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38578
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.... Read more
- EPSS Score: %0.06
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38529
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.... Read more
Affected Products : r7800_firmware r8900_firmware r9000_firmware d7800_firmware d7800 r9000 r8900 r7800- EPSS Score: %1.47
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38459
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. Using the SYSDBA... Read more
Affected Products : versiondog- EPSS Score: %0.22
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38449
Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrite the memory in any location of the affected product.... Read more
Affected Products : versiondog- EPSS Score: %0.27
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38432
FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow an attacker to remotely execute code.... Read more
- EPSS Score: %0.86
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38481
The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker may send a malicious payload that can enable the user to execute another SQL ... Read more
Affected Products : versiondog- EPSS Score: %0.24
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-45237
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort write... Read more
Affected Products : fort-validator- Published: Aug. 24, 2024
- Modified: Aug. 27, 2024