Latest CVE Feed
-
9.8
CRITICALCVE-2017-0907
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys o... Read more
Affected Products : recurly_client_.net- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0906
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.... Read more
Affected Products : recurly_client_python- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-41730
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on ... Read more
- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2017-0903
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to ... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-41717
Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the system.... Read more
Affected Products :- Published: Oct. 22, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2024-41703
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.... Read more
Affected Products : librechat- Published: Jul. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41648
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41646
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2017-0824
An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.... Read more
Affected Products : android- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-41622
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2017-1000047
rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution... Read more
Affected Products : rbenv- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0822
An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63787722.... Read more
Affected Products : android- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-41593
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2763_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware +38 more products- Published: Oct. 03, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2017-0889
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.... Read more
Affected Products : paperclip- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-41570
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.... Read more
Affected Products : havoc- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-41459
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.... Read more
- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41444
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.... Read more
Affected Products : seacms- Published: Aug. 26, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-41372
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.... Read more
Affected Products : organizr- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2019-9023
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data.... Read more
- Published: Feb. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41361
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php... Read more
Affected Products : phoniebox- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024