Latest CVE Feed
-
9.8
CRITICALCVE-2017-15960
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.... Read more
Affected Products : article_directory_script- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15982
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.... Read more
Affected Products : news- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15969
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.... Read more
Affected Products : allsharevideo- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15944
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.... Read more
Affected Products : pan-os- Actively Exploited
- Published: Dec. 11, 2017
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2017-15961
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.... Read more
Affected Products : iproject_management_system- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15909
D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access.... Read more
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15919
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.... Read more
Affected Products : ultimate-form-builder-lite- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15875
SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.... Read more
Affected Products : gpweb- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15958
D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.... Read more
Affected Products : d-park_pro- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-37124
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to... Read more
- Published: Jun. 18, 2024
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2017-15692
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on... Read more
Affected Products : geode- Published: Feb. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15714
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert wi... Read more
Affected Products : ofbiz- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15702
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port... Read more
Affected Products : qpid_broker-j- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-32658
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.... Read more
- Published: Apr. 23, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2024-32041
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gf... Read more
- Published: Apr. 22, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2017-15539
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.... Read more
Affected Products : zorovavi\/blog- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15579
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.... Read more
Affected Products : php_melody- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15607
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.... Read more
Affected Products : otter- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-27280
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may retu... Read more
Affected Products : ruby- Published: May. 14, 2024
- Modified: May. 02, 2025