Latest CVE Feed
-
9.8
CRITICALCVE-2021-2047
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker... Read more
Affected Products : weblogic_server- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7129
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remot... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-34381
Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, le... Read more
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32839
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app terminati... Read more
- Published: Aug. 24, 2022
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2017-7126
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6895
USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.... Read more
Affected Products : usb_pratirodh- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-20892
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arb... Read more
Affected Products : vcenter_server- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6862
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR... Read more
Affected Products : wnr2000v5_firmware wnr2000v4_firmware wnr2000v3_firmware wnr2000v5 wnr2000v4 wnr2000v3- Actively Exploited
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-49400
Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2017-6886
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.... Read more
Affected Products : libraw- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-49286
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Moridrin SSV Events allows PHP Local File Inclusion.This issue affects SSV Events: from n/a through 3.2.7.... Read more
Affected Products : ssv_events- Published: Oct. 20, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2017-6747
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assign... Read more
Affected Products : identity_services_engine- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-24439
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible bec... Read more
- Published: Dec. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6708
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The v... Read more
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-49222
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-23537
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown... Read more
- Published: Dec. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23468
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue.... Read more
- Published: Dec. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22687
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- Published: Mar. 25, 2022
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2022-21420
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network acce... Read more
Affected Products : coherence- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6530
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 do not check password.shtml authorization, leading to Arbitrary password change.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025