Latest CVE Feed
-
9.8
CRITICALCVE-2024-38140
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Aug. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0917
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does n... Read more
Affected Products : vnx1_oe_firmware vnx2_oe_firmware vnxe_oe_firmware vnx5200 vnx5400 vnx5600 vnx5800 vnxe1600 vnxe3100 vnxe3150 +3 more products- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0883
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key ... Read more
Affected Products : operations_manager- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0872
A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.0. WDC stores password credentials in plaintext.... Read more
Affected Products : webdatorcentral- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-37980
Microsoft SQL Server Elevation of Privilege Vulnerability... Read more
Affected Products : sql_server sql_server sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022- Published: Sep. 10, 2024
- Modified: Jan. 07, 2025
-
9.8
CRITICALCVE-2016-0897
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.... Read more
Affected Products : operations_manager- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-9792
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable cr... Read more
- Published: Apr. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0922
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.... Read more
Affected Products : vipr_srm- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-8256
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.... Read more
Affected Products : coldfusion- Published: Dec. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0913
The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC Networker Module for Microsoft 8.2.x before 8.2.3.6 allows remote RM servers to execute arbitrary commands by placing a crafted script ... Read more
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0746
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to ... Read more
- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0718
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.... Read more
Affected Products : firefox ubuntu_linux debian_linux leap python mac_os_x opensuse linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit +4 more products- Published: May. 26, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-7194
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.... Read more
- Actively Exploited
- Published: Dec. 05, 2019
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2016-0726
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.... Read more
Affected Products : nagios- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-0638
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.... Read more
Affected Products : weblogic_server- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-37759
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.... Read more
Affected Products : datagear- Published: Jun. 24, 2024
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2024-37863
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2019-25033
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exp... Read more
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19088
Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.... Read more
Affected Products : gitlab- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37444
Missing Authorization vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.7.1.... Read more
- Published: Nov. 01, 2024
- Modified: May. 28, 2025