Latest CVE Feed
-
9.8
CRITICALCVE-2019-16943
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in ... Read more
Affected Products : fedora debian_linux enterprise_linux_server active_iq_unified_manager webcenter_sites weblogic_server oncommand_workflow_automation steelstore_cloud_integrated_storage communications_cloud_native_core_network_slice_selection_function goldengate_application_adapters +17 more products- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.... Read more
Affected Products : gitea- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2019-16444
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a binary planting (default folder privilege escalation) vulnera... Read more
- Published: Dec. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34756
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)... Read more
- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14195
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.... Read more
Affected Products : u-boot- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13640
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command exec... Read more
Affected Products : qbittorrent- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31314
File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.... Read more
Affected Products : terminal_security_system- Published: Jan. 20, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2019-13107
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c... Read more
- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability... Read more
- Actively Exploited
- Published: May. 11, 2021
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2019-12519
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expressio... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-1213
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. To exploit... Read more
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11705
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.... Read more
Affected Products : thunderbird- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11049
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-free... Read more
- Published: Dec. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10655
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, ... Read more
Affected Products : gac2500_firmware gvc3202_firmware gxv3275_firmware gxv3240_firmware gxp2200_firmware gac2500 gvc3202 gxv3275 gxv3240 gxp2200- Published: Mar. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10053
An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an... Read more
Affected Products : suricata- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4960
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown function of the file interface/sysmanage/licenseauthorization.php. The manipulation of the argument file_uploa... Read more
- Published: May. 16, 2024
- Modified: Jul. 16, 2025
-
9.8
CRITICALCVE-2024-4965
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This issue affects some unknown processing of the file /useratte/resmanage.php. The manipulation of the argument load leads to os comm... Read more
- Published: May. 16, 2024
- Modified: Jul. 15, 2025
-
9.8
CRITICALCVE-2024-4962
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some unknown functionality of the file /useratte/resmanage.php. The manipulation of the argumen... Read more
- Published: May. 16, 2024
- Modified: Jul. 15, 2025
-
9.8
CRITICALCVE-2024-4932
A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Bidding System 1.0. Affected is an unknown function of the file /simple-online-bidding-system/admin/index.php?page=manage_user. The manipulation of the argument i... Read more
Affected Products : simple_online_bidding_system- Published: May. 16, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2024-4936
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code exec... Read more
Affected Products : canto- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024