Latest CVE Feed
-
9.8
CRITICALCVE-2024-34480
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.... Read more
Affected Products : computer_laboratory_management_system- Published: Aug. 07, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2016-3087
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.... Read more
Affected Products : struts- Published: Jun. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2019-2646
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attack... Read more
Affected Products : weblogic_server- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14926
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being r... Read more
- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15562
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm... Read more
Affected Products : gorm- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5212
In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed sui... Read more
Affected Products : nethack- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5213
In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid ... Read more
Affected Products : nethack- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12699
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objd... Read more
- Published: Jun. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-4197
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editi... Read more
- Published: Nov. 06, 2010
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2019-16378
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.... Read more
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25575
An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type confusion flaw when downcasting. NOTE: This vulnerability only affects products that are no longer supported... Read more
Affected Products : failure- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-26972
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a... Read more
Affected Products : firefox- Published: Jan. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-2320
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.... Read more
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34256
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.... Read more
Affected Products : ofcms- Published: May. 14, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2020-28144
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the... Read more
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34204
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.... Read more
- Published: May. 14, 2024
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-34195
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to poten... Read more
- Published: Aug. 28, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2015-2147
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.... Read more
Affected Products : phpbugtracker- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-2146
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id parameter to group.php, the (3) status_id parameter to sta... Read more
Affected Products : phpbugtracker- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2628
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was i... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation curl- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024