Latest CVE Feed
-
9.8
CRITICALCVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to... Read more
- Published: Jun. 18, 2024
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2024-32658
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.... Read more
- Published: Apr. 23, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2024-32041
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gf... Read more
- Published: Apr. 22, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2024-29972
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker... Read more
- Published: Jun. 04, 2024
- Modified: Jan. 22, 2025
-
9.8
CRITICALCVE-2024-29864
Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.... Read more
Affected Products : distrobox- Published: Mar. 21, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-28285
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-27280
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may retu... Read more
Affected Products : ruby- Published: May. 14, 2024
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2024-26304
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (821... Read more
Affected Products : arubaos- Published: May. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24790
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.... Read more
Affected Products : go- Published: Jun. 05, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23473
The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for ... Read more
Affected Products : access_rights_manager- Published: May. 14, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-11693
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderb... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-11403
There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does... Read more
Affected Products : libjxl- Published: Nov. 25, 2024
- Modified: Jul. 24, 2025
-
9.8
CRITICALCVE-2024-10525
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the ... Read more
Affected Products : mosquitto- Published: Oct. 30, 2024
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2024-10467
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2023-49785
NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HT... Read more
Affected Products : nextchat- Published: Mar. 12, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-48793
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.... Read more
Affected Products : manageengine_adaudit_plus- EPSS Score: %8.62
- Published: Feb. 02, 2024
- Modified: Jun. 11, 2025
-
9.8
CRITICALCVE-2023-46747
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which h... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +10 more products- Actively Exploited
- EPSS Score: %94.44
- Published: Oct. 26, 2023
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2023-46222
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.... Read more
- EPSS Score: %1.89
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45849
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner. ... Read more
Affected Products : helix_core- EPSS Score: %0.34
- Published: Nov. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45614
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successf... Read more
- EPSS Score: %0.87
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024