Latest CVE Feed
-
9.8
CRITICALCVE-2021-24045
A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most Re... Read more
Affected Products : hermes- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24042
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior t... Read more
- Published: Jan. 04, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2021-24028
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.... Read more
Affected Products : thrift- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24030
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.... Read more
Affected Products : gameroom- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24025
Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0... Read more
Affected Products : hhvm- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24007
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.... Read more
Affected Products : fortimail- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0244
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted bin... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9912
The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a den... Read more
Affected Products : php- Published: Jan. 04, 2017
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2014-9474
Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors related to incorrect documentation for mpn_set_str.... Read more
Affected Products : gnu_mpfr- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-23909
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23908
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.... Read more
Affected Products : headunit_ntg6_mercedes-benz_user_experience a_220 a_220_4matic e_350 e_350_4matic eqc gle_350 gle_350_4matic- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23847
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP... Read more
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23682
This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly saniti... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23561
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.... Read more
Affected Products : comb- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23792
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to ... Read more
Affected Products : twelvemonkeys- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23558
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)... Read more
Affected Products : bmoor- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23520
The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling... Read more
Affected Products : juce- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-1477
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and applicat... Read more
Affected Products : firefox firefox_esr thunderbird ubuntu_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus +8 more products- Published: Feb. 06, 2014
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2021-23518
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the... Read more
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23507
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/... Read more
Affected Products : object-path-set- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024