Latest CVE Feed
-
9.8
CRITICALCVE-2020-5531
Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number 21121 or before), MELSEC iQ-R Series C Controller Module /... Read more
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-35409
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.... Read more
Affected Products : webid- Published: May. 22, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2018-3750
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existi... Read more
Affected Products : deep_extend- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.... Read more
Affected Products : community_events- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-35355
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection.... Read more
Affected Products : dino_physics_school_assistant- Published: May. 30, 2024
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2024-35368
FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.... Read more
Affected Products : ffmpeg- Published: Nov. 29, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2020-5519
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.... Read more
Affected Products : openlitespeed- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-35359
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.... Read more
Affected Products : dino_physics_school_assistant- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5089
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thu... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-35285
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2020-5505
Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.... Read more
Affected Products : freelancy- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9265
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.... Read more
Affected Products : openvswitch- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9433
Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1Parser.cxx.... Read more
Affected Products : libmwaw- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-35276
A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.... Read more
- Published: Jan. 14, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2018-6551
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region ... Read more
Affected Products : glibc- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.... Read more
Affected Products : rust_sgx_sdk- Published: Jan. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5446
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2090
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-2888
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6182
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025