Latest CVE Feed
-
9.8
CRITICALCVE-2016-2000
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.... Read more
- Published: Apr. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-20005
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more
Affected Products : rest\/json- Published: Jan. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2024
HPE Insight Control before 7.5.1 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.... Read more
- Published: Jun. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-20002
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more
Affected Products : rest\/json- Published: Jan. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2003
HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collectio... Read more
Affected Products : p9000_command_view_advanced_edition_software xp7_command_view_advanced_edition_suite- Published: Apr. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-3347
A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipulation of the argument jet_id leads t... Read more
Affected Products : airline_ticket_reservation_system- Published: Apr. 05, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2016-20017
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.... Read more
- Actively Exploited
- Published: Oct. 19, 2022
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2016-2031
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive... Read more
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1925
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.... Read more
Affected Products : lha_for_unix- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-20009
A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : vxworks sgt-100_firmware sgt-200_firmware sgt-300_firmware sgt-400_firmware sgt-a20_firmware sgt-a35_firmware sgt-a65_firmware sgt-100 sgt-200 +5 more products- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28962
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Junipe... Read more
Affected Products : junos- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32207
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire macos element_software h300s_firmware h500s_firmware h700s_firmware +9 more products- Published: Jul. 07, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2024-3116
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management s... Read more
- Published: Apr. 04, 2024
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2024-3080
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27668
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.8... Read more
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3002
A vulnerability, which was classified as critical, was found in code-projects Online Book System 1.0. Affected is an unknown function of the file /description.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the at... Read more
Affected Products : online_book_system- Published: Mar. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3000
A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument username/password/login_username/login_password leads to sql injecti... Read more
Affected Products : online_book_system- Published: Mar. 27, 2024
- Modified: Feb. 21, 2025
-
9.8
CRITICALCVE-2024-39950
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.... Read more
- Published: Jul. 31, 2024
- Modified: Aug. 19, 2024
-
9.8
CRITICALCVE-2024-39917
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRet... Read more
Affected Products : xrdp- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23943
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.... Read more
- Published: Mar. 14, 2022
- Modified: May. 01, 2025