Latest CVE Feed
-
9.8
CRITICALCVE-2020-28144
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the... Read more
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34204
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.... Read more
- Published: May. 14, 2024
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-34195
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to poten... Read more
- Published: Aug. 28, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2015-2147
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.... Read more
Affected Products : phpbugtracker- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-2146
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id parameter to group.php, the (3) status_id parameter to sta... Read more
Affected Products : phpbugtracker- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2628
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was i... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation curl- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34087
An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 28, 2024
-
9.8
CRITICALCVE-2024-34102
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerabil... Read more
- Actively Exploited
- Published: Jun. 13, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2015-2001
The MetaIO SDK before 6.0.2.1 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.... Read more
Affected Products : metaio_sdk- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-3952
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.... Read more
Affected Products : vcenter_server- Actively Exploited
- Published: Apr. 10, 2020
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2013-4976
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials... Read more
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-2003
The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.... Read more
Affected Products : pjsua2_sdk- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4979
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.... Read more
Affected Products : qradar_security_information_and_event_manager- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-20111
miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, r... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2020-4988
Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or possibly execute code. IBM X-Force ID: 192706.... Read more
Affected Products : loopback- Published: Dec. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33973
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-33972
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-33964
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2016-5257
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execut... Read more
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-33965
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024