Latest CVE Feed
-
9.8
CRITICALCVE-2022-46353
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA... Read more
- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2023-37460
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary fi... Read more
Affected Products : plexus-archiver- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31866
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before ... Read more
Affected Products : zeppelin- Published: Apr. 09, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2015-0152
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31807
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2024-31695
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2024-31678
Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.... Read more
- Published: Apr. 11, 2024
- Modified: Apr. 08, 2025
-
9.8
CRITICALCVE-2024-31546
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.... Read more
Affected Products : computer_laboratory_management_system- Published: Apr. 19, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2014-9984
nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.... Read more
Affected Products : glibc- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-31510
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.... Read more
Affected Products : liboqs- Published: May. 24, 2024
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2014-9939
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.... Read more
Affected Products : binutils- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9921
Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, and remove users via a configuration error.... Read more
Affected Products : cloud_analysis_and_deconstructive_services- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9911
Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact... Read more
Affected Products : international_components_for_unicode- Published: Jan. 04, 2017
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-37434
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source... Read more
Affected Products : fedora debian_linux active_iq_unified_manager ontap_select_deploy_administration_utility macos oncommand_workflow_automation h300s_firmware h500s_firmware h700s_firmware iphone_os +12 more products- Published: Aug. 05, 2022
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2022-37454
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interfac... Read more
- Published: Oct. 21, 2022
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-31470
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point managem... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-31472
There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (82... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2014-9826
ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.... Read more
Affected Products : imagemagick- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9846
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.... Read more
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9766
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025