Latest CVE Feed
-
9.8
CRITICALCVE-2017-10816
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.... Read more
Affected Products : malion- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10804
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database lay... Read more
Affected Products : odoo- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10788
The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss ... Read more
Affected Products : dbd-mysql- Published: Jul. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10818
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the Relay Service.... Read more
Affected Products : malion- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-42383
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-42473
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possi... Read more
Affected Products : openfga- Published: Aug. 12, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-42394
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to ... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-42357
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by ... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-42360
SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shel... Read more
Affected Products : sequenceserver- Published: Aug. 14, 2024
- Modified: Aug. 16, 2024
-
9.8
CRITICALCVE-2017-10685
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.... Read more
Affected Products : ncurses- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10699
avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.... Read more
Affected Products : vlc_media_player- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10615
A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to potentially execute arbitrary code or crash daemons such as telnetd or sshd that make use of PAM. Affected Jun... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-1498
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the... Read more
- Actively Exploited
- Published: May. 06, 2021
- Modified: Feb. 24, 2025
-
9.8
CRITICALCVE-2021-1472
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about ... Read more
Affected Products : rv340_firmware rv340w_firmware rv345_firmware rv345p_firmware rv160_firmware rv160w_firmware rv260_firmware rv260p_firmware rv260w_firmware small_business_rv_series_router_firmware +9 more products- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-10366
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated at... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-42256
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, netfs will call cifs_prepare_write() which will make cifs repick the server for the op befo... Read more
Affected Products : linux_kernel- Published: Aug. 08, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2020-9547
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).... Read more
Affected Products : debian_linux active_iq_unified_manager weblogic_server primavera_unifier jd_edwards_enterpriseone_tools retail_xstore_point_of_service jackson-databind autovue_for_agile_product_lifecycle_management banking_platform communications_evolved_communications_application_server +6 more products- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8606
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.... Read more
Affected Products : interscan_web_security_virtual_appliance- Published: May. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8518
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.... Read more
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7593
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer overflow vulnerability exists in the Web Server functio... Read more
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024