Latest CVE Feed
-
9.8
CRITICALCVE-2024-40765
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.... Read more
Affected Products : sonicos- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2018-5206
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.... Read more
- Published: Jan. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9679
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.... Read more
Affected Products : provisioning_services- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-40624
TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled cookies. One can use php... Read more
Affected Products : torrentpier- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9565
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incom... Read more
Affected Products : nagios- Published: Dec. 15, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2018-20749
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.... Read more
- Published: Jan. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40540
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept.... Read more
Affected Products : my-springsecurity-plus- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40541
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build.... Read more
Affected Products : my-springsecurity-plus- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9537
tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.... Read more
Affected Products : libtiff- Published: Nov. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-40515
An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.... Read more
- Published: Jul. 16, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2016-9534
tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. Reported as MSVR 35095, aka "TIFFFlushData1 heap-buffer-overflow."... Read more
Affected Products : libtiff- Published: Nov. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-40493
Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes `coap_msg_get_p... Read more
Affected Products : freecoap- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
9.8
CRITICALCVE-2024-40486
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.... Read more
Affected Products : live_membership_system- Published: Aug. 12, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-40480
A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct... Read more
Affected Products : online_exam_system- Published: Aug. 12, 2024
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2016-9483
The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to... Read more
Affected Products : php_formmail_generator- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40472
Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."... Read more
Affected Products : daily_calories_monitoring_tool- Published: Aug. 12, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2018-17963
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.... Read more
- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40446
An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script... Read more
Affected Products : mimetex- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
-
9.8
CRITICALCVE-2024-40414
A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.... Read more
- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-16858
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, wou... Read more
Affected Products : libreoffice- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024