Latest CVE Feed
-
9.8
CRITICALCVE-2019-10160
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abus... Read more
Affected Products : ubuntu_linux enterprise_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_tus +5 more products- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-3662
Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Musi... Read more
Affected Products : qca6574au_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware qcs605_firmware apq8009_firmware msm8909w_firmware +56 more products- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-3681
Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.... Read more
Affected Products : -- Published: Jul. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26723
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.... Read more
Affected Products : macos- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38204
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require use... Read more
Affected Products : coldfusion- Published: Sep. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2852
A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based b... Read more
- Published: Mar. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2863
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.... Read more
Affected Products : lg_led_assistant- Published: Mar. 25, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2024-2849
A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. This vulnerability affects unknown code. The manipulation of the argument photo leads to unrestricted upload. The attack can be initiated remotely. The exploit has... Read more
Affected Products : simple_file_manager_web_app- Published: Mar. 23, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2024-2809
A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. Affected is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer ... Read more
- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2771
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions... Read more
Affected Products : contact_form- Published: May. 18, 2024
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2019-9677
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HF... Read more
- Published: Sep. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2723
SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQ... Read more
Affected Products :- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-53908
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs ... Read more
Affected Products : django- Published: Dec. 06, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2022-42808
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2020-29600
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.... Read more
- Published: Dec. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2649
A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /protocol/iscdevicestatus/deleteonlineuser.php. The manipulation of the ... Read more
- Published: Mar. 20, 2024
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2020-10108
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pip... Read more
Affected Products : ubuntu_linux fedora zfs_storage_appliance_kit debian_linux solaris twisted twisted- Published: Mar. 12, 2020
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2024-2604
A vulnerability was found in SourceCodester File Manager App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update-file.php. The manipulation of the argument file leads to unrestricted upload. The atta... Read more
- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2565
A vulnerability was found in PandaXGO PandaX up to 20240310. It has been classified as critical. Affected is an unknown function of the file /apps/system/router/upload.go of the component File Extension Handler. The manipulation of the argument file leads... Read more
Affected Products : pandax- Published: Mar. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2576
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorization bypass. It is ... Read more
- Published: Mar. 18, 2024
- Modified: Feb. 20, 2025