Latest CVE Feed
-
9.8
CRITICALCVE-2017-0889
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.... Read more
Affected Products : paperclip- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-41570
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.... Read more
Affected Products : havoc- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-41459
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.... Read more
- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41444
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.... Read more
Affected Products : seacms- Published: Aug. 26, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-41372
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.... Read more
Affected Products : organizr- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2019-9023
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data.... Read more
- Published: Feb. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41361
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php... Read more
Affected Products : phoniebox- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-41577
An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-41319
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.... Read more
- Published: Jul. 23, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41318
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.... Read more
- Published: Jul. 22, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-41276
A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentia... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2019-7198
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS... Read more
- Published: Dec. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6808
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.... Read more
- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41195
An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-41184
In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.... Read more
Affected Products :- Published: Jul. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41138
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission ... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
9.8
CRITICALCVE-2019-5096
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free cond... Read more
Affected Products : goahead- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5079
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets ca... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41115
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` f... Read more
Affected Products : streamlit-geospatial- Published: Jul. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18814
An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024