Latest CVE Feed
-
9.8
CRITICALCVE-2017-15994
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code h... Read more
Affected Products : rsync- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-2294
Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.... Read more
Affected Products : open_web_analytics- Published: Apr. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29592
An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload allows an attacker to upload dangerous executables that bypass the file types allowed (regardless of the fil... Read more
Affected Products : orchard- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28639
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.... Read more
- Published: Mar. 16, 2024
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2020-29511
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of proc... Read more
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29507
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.... Read more
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28556
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.... Read more
Affected Products : php_task_management_system- Published: Apr. 15, 2024
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2020-29509
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of pr... Read more
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28553
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.... Read more
Affected Products : ac18_firmware- Published: Mar. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28285
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2073
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus."... Read more
Affected Products : catia- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28200
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-abl... Read more
Affected Products : n-central- Published: Jul. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8911
An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.... Read more
Affected Products : tnef- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-2023
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_t... Read more
Affected Products : tapatalk- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-9493
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.... Read more
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28056
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" re... Read more
Affected Products : amplify_cli- Published: Apr. 15, 2024
- Modified: Jun. 30, 2025
-
9.8
CRITICALCVE-2018-6959
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.... Read more
Affected Products : vrealize_automation- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29283
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.... Read more
Affected Products : online_doctor_appointment_booking_system_php_and_mysql- Published: Dec. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8088
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 ... Read more
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5430
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerabil... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024