Latest CVE Feed
-
9.8
CRITICALCVE-2024-53677
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue ... Read more
Affected Products : struts- Published: Dec. 11, 2024
- Modified: Jul. 15, 2025
-
9.8
CRITICALCVE-2025-7483
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. This issue affects some unknown processing of the file /users/forgot-password.php. The manipulation of the argument email leads to sql injection... Read more
Affected Products : vehicle_parking_management_system- Published: Jul. 12, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7523
A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.aspx. The manipulation leads to xml external entity reference. The attack may... Read more
Affected Products : jinher_oa- Published: Jul. 13, 2025
- Modified: Aug. 26, 2025
- Vuln Type: XML External Entity
-
9.8
CRITICALCVE-2020-3376
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failu... Read more
- EPSS Score: %0.89
- Published: Jul. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-4906
A vulnerability was found in PHPGurukul Notice Board System 1.0. It has been classified as critical. Affected is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the att... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2018-14357
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.... Read more
- EPSS Score: %2.28
- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7912
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.... Read more
- EPSS Score: %0.65
- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-3223
Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/so... Read more
- EPSS Score: %5.48
- Published: Jul. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18342
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.... Read more
- EPSS Score: %4.82
- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10074
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail add... Read more
Affected Products : swiftmailer- EPSS Score: %75.14
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2014-4678
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.... Read more
- EPSS Score: %4.73
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-43973
An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.... Read more
Affected Products : gobgp- Published: Apr. 21, 2025
- Modified: May. 08, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-27836
An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.... Read more
Affected Products : ghostscript- Published: Mar. 25, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-8695
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.... Read more
Affected Products : desktop- Published: Sep. 12, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-0057
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 .net_framework windows_server_2019 visual_studio_2019 visual_studio windows_10_1607 windows_10_1809 windows_10_21h2 +10 more products- EPSS Score: %2.35
- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Actively Exploited
- EPSS Score: %90.96
- Published: Jul. 19, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2022-25765
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.... Read more
- EPSS Score: %87.86
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-47274
In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [16... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2021-33640
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).... Read more
- EPSS Score: %0.19
- Published: Dec. 19, 2022
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2021-26877
Windows DNS Server Remote Code Execution Vulnerability... Read more
- EPSS Score: %8.77
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024