Latest CVE Feed
-
9.8
CRITICALCVE-2014-125082
A vulnerability was found in nivit redports. It has been declared as critical. This vulnerability affects unknown code of the file redports-trac/redports/model.py. The manipulation leads to sql injection. The name of the patch is fc2c1ea1b8d795094abb15ac7... Read more
Affected Products : redports- EPSS Score: %0.06
- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-1999-1324
VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force pass... Read more
Affected Products : openvms_vax- EPSS Score: %1.01
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-28303
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.... Read more
Affected Products :- Published: Mar. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11887
SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.... Read more
Affected Products : simplybook- EPSS Score: %2.13
- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000533
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using... Read more
Affected Products : gitlist- EPSS Score: %93.25
- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12757
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated G... Read more
Affected Products : vault- EPSS Score: %0.36
- Published: Jun. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4193
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.... Read more
Affected Products : security_guardium- EPSS Score: %0.41
- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.... Read more
Affected Products : on_demand_marketplace_script- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-18634
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.... Read more
Affected Products : newspaper- EPSS Score: %1.08
- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3727
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes conta... Read more
Affected Products : oh_my_zsh- EPSS Score: %1.36
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2001-0395
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.... Read more
- EPSS Score: %1.13
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.... Read more
Affected Products : basic_job_site_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.... Read more
Affected Products : bus_booking_script- EPSS Score: %2.51
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-35314
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.... Read more
Affected Products : wondercms- EPSS Score: %39.57
- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17651
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.... Read more
Affected Products : paid_to_read_script- EPSS Score: %2.51
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12414
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.... Read more
Affected Products : format_factory- EPSS Score: %0.51
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2001-1155
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.... Read more
Affected Products : freebsd- EPSS Score: %0.47
- Published: Aug. 23, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-21784
An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- EPSS Score: %0.40
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22480
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.... Read more
Affected Products : harmonyos- EPSS Score: %0.24
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17198
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML ... Read more
Affected Products : roller- EPSS Score: %0.90
- Published: May. 28, 2019
- Modified: Nov. 21, 2024