Latest CVE Feed
-
9.8
CRITICALCVE-2018-6908
An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in th... Read more
- EPSS Score: %4.28
- Published: Nov. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18662
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used t... Read more
Affected Products : youphptube- EPSS Score: %0.30
- Published: Nov. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10528
Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Mus... Read more
Affected Products : sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sd_675_firmware sdx24_firmware mdm9650_firmware +46 more products- EPSS Score: %0.40
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-52440
Deserialization of Untrusted Data vulnerability in Bueno Labs Pvt. Ltd. Xpresslane Fast Checkout allows Object Injection.This issue affects Xpresslane Fast Checkout: from n/a through 1.0.0.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2159
Monkey HTTP Daemon: broken user name authentication... Read more
Affected Products : monkey- EPSS Score: %0.46
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.42
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-5867
HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability... Read more
Affected Products : ht_editor- EPSS Score: %1.08
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7245
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one must register wi... Read more
Affected Products : ctfd- EPSS Score: %0.38
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2198
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.... Read more
Affected Products : login_security- EPSS Score: %0.53
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2025
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an... Read more
Affected Products : intrexx- EPSS Score: %9.01
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-5741
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.... Read more
- EPSS Score: %1.75
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10119
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).... Read more
Affected Products : cpanel- EPSS Score: %2.83
- Published: Mar. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10806
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the v... Read more
- EPSS Score: %2.83
- Published: Mar. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20549
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets) software. A heap out-of-bounds access can occur during LE Packet reception in Broadcom Bluetooth. The Samsung ID is SVE-2019-15724 (November 2019).... Read more
- EPSS Score: %0.15
- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1964
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-50... Read more
Affected Products : heron- EPSS Score: %9.86
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21133
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.... Read more
- EPSS Score: %0.56
- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19167
Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution.... Read more
- EPSS Score: %0.46
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7646
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.... Read more
Affected Products : curlrequest- EPSS Score: %0.18
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-14472
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- EPSS Score: %1.06
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9576
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : magento- EPSS Score: %3.10
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024