Latest CVE Feed
-
9.8
CRITICALCVE-2020-19510
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.... Read more
- EPSS Score: %0.43
- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16848
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.... Read more
- EPSS Score: %9.45
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15143
Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.... Read more
Affected Products : openemr- EPSS Score: %0.02
- Published: Aug. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10991
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.... Read more
Affected Products : webaccess- EPSS Score: %24.59
- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18346
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.... Read more
Affected Products : cms_web-gooroo- EPSS Score: %1.32
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-2302
While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead to heap overflow. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT... Read more
Affected Products : qca6574au_firmware sdm660_firmware sm8150_firmware msm8996au_firmware apq8096au_firmware qca6174a_firmware qca9377_firmware qcs605_firmware sdx24_firmware mdm9650_firmware +50 more products- EPSS Score: %0.40
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1916
An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all versions between 4.57.0 and 4.78.0, 4.79.0, 4.80.0, 4.81.0,... Read more
Affected Products : hhvm- EPSS Score: %0.66
- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29658
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.... Read more
- EPSS Score: %14.95
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35733
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthentic... Read more
Affected Products : udr-ja1004_firmware udr-ja1008_firmware udr-ja1016_firmware udr-ja1004 udr-ja1008 udr-ja1016- EPSS Score: %1.45
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5452
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff... Read more
Affected Products : pytorch_lightning- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48648
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Ex... Read more
- EPSS Score: %0.73
- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22074
Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. This is fixed in 1.8.2014, 1.7.4212, 1.6.32... Read more
Affected Products : dynamsoft_service- Published: Jun. 06, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2016-9403
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.... Read more
- EPSS Score: %5.33
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-20426
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.... Read more
- EPSS Score: %0.07
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-20092
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.... Read more
Affected Products : articlecms- EPSS Score: %0.43
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34755
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.... Read more
- EPSS Score: %33.24
- Published: Jun. 14, 2023
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2023-3050
Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass.This issue affects Lockcell: before 15. ... Read more
- EPSS Score: %0.03
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29129
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendi... Read more
Affected Products : saml- EPSS Score: %0.07
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-1187
Bitlbee does not drop extra group privileges correctly in unix.c... Read more
Affected Products : bitlbee- EPSS Score: %0.43
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7913
A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. The manipulation of the argument lname/fname/mi/address/contact/meterReader leads to sql i... Read more
Affected Products : billing_system- Published: Aug. 18, 2024
- Modified: Aug. 19, 2024