Latest CVE Feed
-
9.8
CRITICALCVE-2016-1352
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.... Read more
Affected Products : unified_computing_system_central_software- Published: Apr. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1341
Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079.... Read more
- Published: Feb. 24, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-39736
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, includin... Read more
- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39742
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.... Read more
Affected Products : mq_operator- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1283
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, w... Read more
- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-39727
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions... Read more
- Published: Dec. 25, 2024
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2017-14008
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access... Read more
Affected Products : centricity_pacs_ra1000- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0699
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.... Read more
Affected Products : shapelib- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2016-1245
It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ ... Read more
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-0547
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially corre... Read more
- Published: Mar. 18, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2016-1239
duck before 0.10 did not properly handle loading of untrusted code from the current directory.... Read more
Affected Products : duck- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39685
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the resample function, which leads to arbitrary command execution. This af... Read more
Affected Products : bert-vits2- Published: Jul. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39705
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.... Read more
Affected Products : nltk- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1114
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.... Read more
Affected Products : coldfusion- Published: May. 11, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-39653
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.... Read more
Affected Products : vikrentcar- Published: Aug. 29, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-39583
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges... Read more
Affected Products : insightiq- Published: Sep. 10, 2024
- Modified: Sep. 16, 2024
-
9.8
CRITICALCVE-2021-43300
Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.... Read more
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15042
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file`... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2016-15040
The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2016-15034
A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedomrss_search of the file freedomrss_search.php. The manipulation leads to sql injection. Upgrading to version 3.2-20180305 is able to add... Read more
Affected Products : dynacase_webdesk- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024