Latest CVE Feed
-
9.8
CRITICALCVE-2021-22566
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kernel-mode pages fr... Read more
Affected Products : fuchsia- EPSS Score: %0.01
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22431
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.... Read more
- EPSS Score: %0.25
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18345
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.... Read more
Affected Products : joomanager- EPSS Score: %3.33
- Published: Aug. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22426
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.... Read more
- EPSS Score: %0.25
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22375
There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality,availability and integrity.... Read more
- EPSS Score: %0.24
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18264
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5... Read more
- EPSS Score: %0.32
- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22345
There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds memory write.... Read more
- EPSS Score: %0.24
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18287
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter.... Read more
Affected Products : stats- EPSS Score: %0.24
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18269
An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans t... Read more
- EPSS Score: %1.98
- Published: May. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18289
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.... Read more
Affected Products : stats- EPSS Score: %0.24
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18211
In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.... Read more
- EPSS Score: %0.39
- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18194
SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter.... Read more
Affected Products : hamayeshnegar_cms- EPSS Score: %0.53
- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18197
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.... Read more
Affected Products : mxgraph- EPSS Score: %0.25
- Published: Feb. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.67
- Published: Feb. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18187
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.... Read more
- EPSS Score: %0.56
- Published: Feb. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-2103
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or ... Read more
- EPSS Score: %25.85
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-21994
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.... Read more
- EPSS Score: %0.10
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22002
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to fa... Read more
Affected Products : linux_kernel cloud_foundation vrealize_suite_lifecycle_manager identity_manager workspace_one_access- EPSS Score: %0.40
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18045
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.... Read more
Affected Products : directadmin- EPSS Score: %0.69
- Published: Jan. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-1744
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly... Read more
Affected Products : weblogic_server- EPSS Score: %0.72
- Published: May. 24, 2005
- Modified: Apr. 03, 2025