Latest CVE Feed
-
9.8
CRITICALCVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.... Read more
Affected Products : gitea- EPSS Score: %0.16
- Published: Oct. 16, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2019-16444
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a binary planting (default folder privilege escalation) vulnera... Read more
- EPSS Score: %1.25
- Published: Dec. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14195
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.... Read more
Affected Products : u-boot- EPSS Score: %0.42
- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13640
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command exec... Read more
Affected Products : qbittorrent- EPSS Score: %4.24
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13107
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c... Read more
- EPSS Score: %0.61
- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12519
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expressio... Read more
- EPSS Score: %9.00
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-1213
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. To exploit... Read more
- EPSS Score: %12.89
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11830
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.... Read more
- EPSS Score: %2.54
- Published: May. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11705
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.... Read more
Affected Products : thunderbird- EPSS Score: %8.71
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11049
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-free... Read more
- EPSS Score: %1.97
- Published: Dec. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10655
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, ... Read more
Affected Products : gac2500_firmware gvc3202_firmware gxv3275_firmware gxv3240_firmware gxp2200_firmware gac2500 gvc3202 gxv3275 gxv3240 gxp2200- EPSS Score: %85.16
- Published: Mar. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-1010238
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. ... Read more
- EPSS Score: %2.94
- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10053
An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an... Read more
Affected Products : suricata- EPSS Score: %0.61
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-0006
A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can result in a crash of... Read more
- EPSS Score: %5.92
- Published: Jan. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8919
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.... Read more
- EPSS Score: %0.26
- Published: Dec. 24, 2018
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2018-8800
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.... Read more
- EPSS Score: %6.79
- Published: Feb. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8786
FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.... Read more
- EPSS Score: %21.92
- Published: Nov. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7761
A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow arbitrary code execution.... Read more
Affected Products : 140cpu65150_firmware 140cpu65160_firmware bmxnor0200h_firmware modicon_m340_bmxp341000_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342000_firmware modicon_m340_bmxp3420102_firmware modicon_m340_bmxp342020h_firmware modicon_m340_bmxp3420302_firmware modicon_m340_bmxp3420302h_firmware +104 more products- EPSS Score: %0.58
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7753
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allo... Read more
Affected Products : bleach- EPSS Score: %0.54
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is complet... Read more
- EPSS Score: %20.89
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024