Latest CVE Feed
-
9.8
CRITICALCVE-2017-6747
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assign... Read more
Affected Products : identity_services_engine- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-24439
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible bec... Read more
- Published: Dec. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6708
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The v... Read more
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-49222
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-23537
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown... Read more
- Published: Dec. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23468
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue.... Read more
- Published: Dec. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22687
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- Published: Mar. 25, 2022
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2022-21420
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network acce... Read more
Affected Products : coherence- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6530
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 do not check password.shtml authorization, leading to Arbitrary password change.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-4177
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-2 that are running only on premis... Read more
Affected Products : gravityzone- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6506
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.... Read more
Affected Products : data_expert_ultimate- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6465
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.... Read more
Affected Products : ftpshell_client- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6532
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-0839
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.... Read more
- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6349
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.... Read more
Affected Products : vim- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6403
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-48887
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request... Read more
- Published: Apr. 08, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-48886
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManage... Read more
Affected Products : fortimanager fortios fortiproxy fortianalyzer fortianalyzer_cloud fortimanager_cloud- Published: Jan. 14, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2017-6274
An elevation of Privilege vulnerability exists in the Thermal Driver, where a missing bounds checks in the thermal throttle driver can cause an out-of-bounds write in the kernel. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A... Read more
Affected Products : android- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-48845
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; ... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024