Latest CVE Feed
-
9.8
CRITICALCVE-2016-2090
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.... Read more
- EPSS Score: %1.94
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-2888
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.... Read more
- EPSS Score: %0.70
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6182
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.... Read more
- EPSS Score: %14.26
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2141
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within ... Read more
- EPSS Score: %0.88
- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-0036
When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed without error, but the... Read more
Affected Products : junos- EPSS Score: %0.26
- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10137
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the ... Read more
- EPSS Score: %8.94
- Published: Jul. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-35099
TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.... Read more
- Published: May. 14, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-35079
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.... Read more
Affected Products : inxedu- Published: May. 23, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2017-7863
FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.... Read more
- EPSS Score: %1.88
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-2780
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.... Read more
Affected Products : berta_cms- EPSS Score: %31.92
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-34927
A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 23, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2015-2784
The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.... Read more
Affected Products : papercrop- EPSS Score: %0.42
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34832
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.... Read more
Affected Products : cubecart- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34802
Missing Authorization vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.... Read more
Affected Products : adfoxly- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5327
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this v... Read more
Affected Products : security_management_server- EPSS Score: %5.04
- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-2798
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : contact_form_maker- EPSS Score: %1.00
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-11831
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.ph... Read more
- EPSS Score: %3.02
- Published: May. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9264
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered ... Read more
Affected Products : openvswitch- EPSS Score: %0.78
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-14362
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.... Read more
- EPSS Score: %5.40
- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5311
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.... Read more
- EPSS Score: %1.21
- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024