Latest CVE Feed
-
9.8
CRITICALCVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary file... Read more
Affected Products : artifactory- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.... Read more
- Actively Exploited
- Published: Dec. 30, 2016
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2016-1000282
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.... Read more
Affected Products : haraka- Published: Feb. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1000027
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentic... Read more
Affected Products : spring_framework- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000156
Mailcwp remote file upload vulnerability incomplete fix v1.100... Read more
Affected Products : mailcwp- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2020-12812
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the ca... Read more
Affected Products : fortios- Actively Exploited
- Published: Jul. 24, 2020
- Modified: Feb. 24, 2025
-
9.8
CRITICALCVE-2024-38076
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability... Read more
- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12460
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause re... Read more
- Published: Jul. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000030
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploita... Read more
- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0930
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period ... Read more
Affected Products : operations_manager- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-38140
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Aug. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0917
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does n... Read more
Affected Products : vnx1_oe_firmware vnx2_oe_firmware vnxe_oe_firmware vnx5200 vnx5400 vnx5600 vnx5800 vnxe1600 vnxe3100 vnxe3150 +3 more products- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0883
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key ... Read more
Affected Products : operations_manager- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0872
A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.0. WDC stores password credentials in plaintext.... Read more
Affected Products : webdatorcentral- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-37980
Microsoft SQL Server Elevation of Privilege Vulnerability... Read more
Affected Products : sql_server sql_server sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022- Published: Sep. 10, 2024
- Modified: Jan. 07, 2025
-
9.8
CRITICALCVE-2016-0897
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.... Read more
Affected Products : operations_manager- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-9792
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable cr... Read more
- Published: Apr. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0922
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.... Read more
Affected Products : vipr_srm- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-8256
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.... Read more
Affected Products : coldfusion- Published: Dec. 19, 2019
- Modified: Nov. 21, 2024