Latest CVE Feed
-
9.8
CRITICALCVE-2019-10137
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the ... Read more
- Published: Jul. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-35099
TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.... Read more
- Published: May. 14, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-35079
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.... Read more
Affected Products : inxedu- Published: May. 23, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2017-7863
FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.... Read more
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-2780
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.... Read more
Affected Products : berta_cms- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-34927
A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 23, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2015-2784
The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.... Read more
Affected Products : papercrop- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34832
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.... Read more
Affected Products : cubecart- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34802
Missing Authorization vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.... Read more
Affected Products : adfoxly- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5327
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this v... Read more
Affected Products : security_management_server- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-2798
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : contact_form_maker- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-11831
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.ph... Read more
- Published: May. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9264
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered ... Read more
Affected Products : openvswitch- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-14362
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.... Read more
- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5311
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.... Read more
- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12525
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this t... Read more
- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1430
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key... Read more
- Published: Dec. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2018-15751
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).... Read more
Affected Products : salt- Published: Oct. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5282
In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrary shell execution,which can compromise the bot This is patched in version 1.0.0-beta... Read more
Affected Products : nick_chan_bot- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15717
Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.... Read more
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024