Latest CVE Feed
-
10.0
HIGHCVE-2011-1505
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.... Read more
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2021-0430
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not neede... Read more
Affected Products : android- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1034
SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.... Read more
Affected Products : tasklist- Published: Mar. 20, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2017-13282
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitat... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8584
Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.... Read more
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-34084
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.... Read more
Affected Products : s3-uploader- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-31794
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject ... Read more
- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-7364
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to exe... Read more
Affected Products : zxin10- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2020-8899
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer... Read more
Affected Products : android- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-7689
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.... Read more
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2021-35003
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists withi... Read more
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-13997
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script... Read more
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2021-27113
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.... Read more
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-17269
Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.... Read more
Affected Products : remote_access- Published: Oct. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3654
u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M... Read more
Affected Products : qca6390_firmware qca6574au_firmware sa6155p_firmware sa8155p_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware +72 more products- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3657
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,... Read more
Affected Products : qca6574au_firmware ipq6018_firmware ipq8064_firmware ipq8074_firmware qrb5165_firmware sdx55_firmware sdm660_firmware sm8250_firmware msm8996au_firmware apq8096au_firmware +64 more products- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-25074
TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44622
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request.... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-32449
TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.... Read more
- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-25913
Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. ... Read more
Affected Products : moveto- Published: Feb. 26, 2024
- Modified: May. 08, 2025