Latest CVE Feed
-
9.8
CRITICALCVE-2021-24212
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.... Read more
Affected Products : help_scout- EPSS Score: %3.31
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24285
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in ... Read more
Affected Products : cars-seller-auto-classifieds-script- EPSS Score: %85.67
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24236
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid ima... Read more
Affected Products : imagements- EPSS Score: %74.93
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-43237
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2021-24240
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.... Read more
Affected Products : business_hours_pro- EPSS Score: %8.07
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24223
The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand()))... Read more
Affected Products : n5_upload_form- EPSS Score: %0.92
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000221
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially cra... Read more
Affected Products : pkgconf- EPSS Score: %0.45
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24171
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "bl... Read more
- EPSS Score: %0.61
- Published: Apr. 05, 2021
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2018-1000155
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller. that can result in Denial of S... Read more
Affected Products : openflow- EPSS Score: %0.50
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000140
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsysl... Read more
- EPSS Score: %43.63
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000123
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data l... Read more
Affected Products : ios_keychain- EPSS Score: %0.34
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000059
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.... Read more
Affected Products : validform_builder- EPSS Score: %0.27
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000007
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redire... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation curl enterprise_linux_server_aus enterprise_linux_server_eus m10-1_firmware m10-4_firmware +10 more products- EPSS Score: %6.77
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-2136
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker... Read more
Affected Products : weblogic_server- EPSS Score: %4.80
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000125
inversoft prime-jwt version prior to version 1.3.0 or prior to commit 0d94dcef0133d699f21d217e922564adbb83a227 contains an input validation vulnerability in JWTDecoder.decode that can result in a JWT that is decoded and thus implicitly validated even if i... Read more
Affected Products : prime-jwt- EPSS Score: %0.43
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-25291
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differ... Read more
- Published: Mar. 12, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.... Read more
- EPSS Score: %4.19
- Published: Dec. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0681
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.... Read more
- EPSS Score: %1.06
- Published: Nov. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0668
Buffer overflow in INplc-RT 3.08 and earlier allows remote attackers to cause denial-of-service (DoS) condition that may result in executing arbtrary code via unspecified vectors.... Read more
Affected Products : inplc-rt- EPSS Score: %1.09
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0669
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability than CVE-2018-0670.... Read more
Affected Products : inplc-rt- EPSS Score: %0.92
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024