Latest CVE Feed
-
9.8
CRITICALCVE-2020-12500
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administr... Read more
Affected Products : es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmware +17 more products- EPSS Score: %6.46
- Published: Oct. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11945
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short ... Read more
- EPSS Score: %22.07
- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11722
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.... Read more
Affected Products : dungeon_crawl_stone_soup- EPSS Score: %3.64
- Published: Apr. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31579
Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Applia... Read more
- EPSS Score: %0.46
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31726
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).... Read more
- EPSS Score: %4.42
- Published: Apr. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31574
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploi... Read more
- EPSS Score: %2.50
- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2021-31556
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.... Read more
- EPSS Score: %0.87
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10038
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the device's web server might be able to execute administrative commands without authentication.... Read more
Affected Products : sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware sicam_mmu sicam_sgu sicam_t- EPSS Score: %0.39
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31531
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).... Read more
Affected Products : manageengine_servicedesk_plus_msp- EPSS Score: %5.64
- Published: Jun. 29, 2021
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2021-31535
LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests wi... Read more
- EPSS Score: %2.60
- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9805
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.... Read more
Affected Products : firefox- EPSS Score: %0.42
- Published: Apr. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9670
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.... Read more
Affected Products : zimbra_collaboration_suite- Actively Exploited
- EPSS Score: %94.43
- Published: May. 29, 2019
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2019-9095
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and gain administra... Read more
Affected Products : mb3170_firmware mb3270_firmware mb3180_firmware mb3280_firmware mb3480_firmware mb3660_firmware mb3170 mb3270 mb3180 mb3280 +2 more products- EPSS Score: %0.12
- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8660
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.... Read more
- EPSS Score: %4.68
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10232
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.... Read more
- EPSS Score: %1.41
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8287
TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.... Read more
Affected Products : tightvnc- EPSS Score: %2.20
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8257
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful e... Read more
- EPSS Score: %20.74
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8206
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lea... Read more
- EPSS Score: %3.30
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8016
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Success... Read more
- EPSS Score: %7.29
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-7192
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.... Read more
- Actively Exploited
- EPSS Score: %94.30
- Published: Dec. 05, 2019
- Modified: Feb. 13, 2025