Latest CVE Feed
-
9.8
CRITICALCVE-2020-8752
Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access.... Read more
- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8645
An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.Jo... Read more
Affected Products : simplejobscript- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4373
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2... Read more
- Published: Jan. 10, 2012
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2020-8597
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.... Read more
Affected Products : ubuntu_linux debian_linux ruggedcom_rm1224_firmware point-to-point_protocol pfc_firmware pfc100 pfc200- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8521
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql... Read more
Affected Products : phpzag- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8519
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql... Read more
Affected Products : phpzag- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8600
Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.... Read more
Affected Products : worry-free_business_security- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-0657
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote atta... Read more
Affected Products : windows_7 windows_server_2008 windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2020-8447
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analysisd p... Read more
Affected Products : ossec- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8540
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML req... Read more
Affected Products : manageengine_desktop_central- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-0748
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.... Read more
- Published: Oct. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-0211
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a... Read more
- Published: Jul. 28, 2010
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2020-8239
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.... Read more
Affected Products : pulse_secure_desktop_client- Published: Oct. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8159
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.... Read more
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-6237
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."... Read more
Affected Products : ip360- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2008-7315
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.... Read more
Affected Products : ui\- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-8113
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.... Read more
Affected Products : gitlab- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8129
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.... Read more
Affected Products : script-manager- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8137
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.... Read more
Affected Products : blamer- Published: Mar. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8086
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a ... Read more
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024