Latest CVE Feed
-
10.0
HIGHCVE-2015-1801
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corruption) or gain privileges.... Read more
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2020-12133
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.... Read more
Affected Products : electric_consciousmap- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-15746
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.... Read more
Affected Products : sitos_six- Published: Oct. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-1283
Code Injection in GitHub repository builderio/qwik prior to 0.21.0. ... Read more
- Published: Mar. 08, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-1424
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service... Read more
Affected Products : melsec_iq-fx5u-32mt\/es_firmware melsec_iq-fx5u-32mt\/ds_firmware melsec_iq-fx5u-32mt\/ess_firmware melsec_iq-fx5u-32mt\/dss_firmware melsec_iq-fx5u-32mr\/es_firmware melsec_iq-fx5u-32mr\/ds_firmware melsec_iq-fx5u-32mr\/ess_firmware melsec_iq-fx5u-32mr\/dss_firmware melsec_iq-fx5u-64mt\/es_firmware melsec_iq-fx5u-64mt\/ds_firmware +68 more products- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-0488
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arb... Read more
- Published: Jan. 18, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1390
Unspecified vulnerability in the Miso (com.bazaarlabs.miso) application 2.2 for Android has unknown impact and attack vectors.... Read more
- Published: Mar. 07, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-2842
Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable ex... Read more
Affected Products : goadmin_ce- Published: May. 12, 2015
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2023-1748
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and... Read more
Affected Products : nxal-100_firmware nxg-100b_firmware nxpg-100w_firmware nxg-200_firmware nxal-100 nxg-100b nxpg-100w nxg-200- Published: Apr. 04, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-4617
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home ap... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
10.0
CRITICALCVE-2021-27470
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary comma... Read more
Affected Products : factorytalk_assetcentre- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-4767
Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors.... Read more
Affected Products : eucalyptus- Published: Oct. 10, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-5757
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST ... Read more
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-2024
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.... Read more
Affected Products : openblue_enterprise_manager_data_collector- Published: May. 18, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-27957
Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1. ... Read more
Affected Products : pie_register- Published: Mar. 17, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-22578
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.... Read more
Affected Products : sequelize- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-6016
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspe... Read more
- Published: Dec. 31, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2013-0361
Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a diff... Read more
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-4704
Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.... Read more
Affected Products : codesys_gateway-server- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2007-1421
Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in include... Read more
Affected Products : premod_subdog- Published: Mar. 13, 2007
- Modified: Apr. 09, 2025