Latest CVE Feed
-
9.8
CRITICALCVE-2024-42005
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.... Read more
Affected Products : django- Published: Aug. 07, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2024-41779
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remo... Read more
- Published: Nov. 22, 2024
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2017-9821
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.... Read more
Affected Products : bharat_interface_for_money_\(bhim\)- EPSS Score: %0.58
- Published: Aug. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9834
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.... Read more
Affected Products : watupro- EPSS Score: %12.47
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9741
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.... Read more
Affected Products : projectsend- EPSS Score: %0.80
- Published: Jun. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-3863
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunder... Read more
- Published: Apr. 16, 2024
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.... Read more
Affected Products : struts- Actively Exploited
- EPSS Score: %94.26
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9771
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_password parameter.... Read more
Affected Products : websitebaker- EPSS Score: %0.78
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9728
In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression.... Read more
Affected Products : uclibc- EPSS Score: %0.41
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9626
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.... Read more
- EPSS Score: %0.33
- Published: Mar. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9664
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring tools without any authorization over ... Read more
- EPSS Score: %2.20
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9602
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user ca... Read more
- EPSS Score: %7.38
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9544
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary ... Read more
- EPSS Score: %48.34
- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-33874
HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.... Read more
Affected Products : hdf5- Published: May. 14, 2024
- Modified: Apr. 18, 2025
-
9.8
CRITICALCVE-2024-32039
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workarou... Read more
- Published: Apr. 22, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2017-9431
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.... Read more
Affected Products : grpc- EPSS Score: %0.83
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9426
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.... Read more
Affected Products : facetag- EPSS Score: %1.56
- Published: Feb. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9417
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.... Read more
- EPSS Score: %42.67
- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9458
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive i... Read more
Affected Products : pan-os- EPSS Score: %1.04
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9385
An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface which allows the highest privileges a user can obtain on the device. This web interface uses root as the use... Read more
- EPSS Score: %0.86
- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024