Latest CVE Feed
-
9.8
CRITICALCVE-2010-5330
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 fo... Read more
Affected Products : airos- Actively Exploited
- EPSS Score: %52.72
- Published: Jun. 11, 2019
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2019-10126
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.... Read more
Affected Products : linux_kernel ubuntu_linux enterprise_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_tus +16 more products- EPSS Score: %0.74
- Published: Jun. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15519
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).... Read more
Affected Products : cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware mx41x_firmware mx51x_firmware xm1145_firmware mx61x_firmware xm3150_firmware +54 more products- EPSS Score: %0.54
- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14531
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.... Read more
Affected Products : the_sleuth_kit- EPSS Score: %0.40
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10904
The olimometer plugin before 2.57 for WordPress has SQL injection.... Read more
Affected Products : olimometer- EPSS Score: %0.55
- Published: Aug. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15564
The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.... Read more
Affected Products : compassion_switzerland- EPSS Score: %0.26
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15646
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.... Read more
- EPSS Score: %0.65
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16256
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instruction... Read more
- Actively Exploited
- EPSS Score: %42.68
- Published: Sep. 12, 2019
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2019-13918
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable s... Read more
Affected Products : sinema_remote_connect_server- EPSS Score: %0.48
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10071
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the correct... Read more
Affected Products : tapestry- EPSS Score: %9.82
- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6908
An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in th... Read more
- EPSS Score: %4.28
- Published: Nov. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18662
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used t... Read more
Affected Products : youphptube- EPSS Score: %0.30
- Published: Nov. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10528
Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Mus... Read more
Affected Products : sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sd_675_firmware sdx24_firmware mdm9650_firmware +46 more products- EPSS Score: %0.40
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-52440
Deserialization of Untrusted Data vulnerability in Bueno Labs Pvt. Ltd. Xpresslane Fast Checkout allows Object Injection.This issue affects Xpresslane Fast Checkout: from n/a through 1.0.0.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2159
Monkey HTTP Daemon: broken user name authentication... Read more
Affected Products : monkey- EPSS Score: %0.46
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.42
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-5867
HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability... Read more
Affected Products : ht_editor- EPSS Score: %1.08
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7245
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one must register wi... Read more
Affected Products : ctfd- EPSS Score: %0.38
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2198
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.... Read more
Affected Products : login_security- EPSS Score: %0.53
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2025
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an... Read more
Affected Products : intrexx- EPSS Score: %9.01
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024