Latest CVE Feed
-
9.8
CRITICALCVE-2024-11693
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderb... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-11403
There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does... Read more
Affected Products : libjxl- Published: Nov. 25, 2024
- Modified: Jul. 24, 2025
-
9.8
CRITICALCVE-2024-10525
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the ... Read more
Affected Products : mosquitto- Published: Oct. 30, 2024
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2024-10467
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2023-49785
NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HT... Read more
Affected Products : nextchat- Published: Mar. 12, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-48793
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.... Read more
Affected Products : manageengine_adaudit_plus- EPSS Score: %8.62
- Published: Feb. 02, 2024
- Modified: Jun. 11, 2025
-
9.8
CRITICALCVE-2023-46747
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which h... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +10 more products- Actively Exploited
- EPSS Score: %94.44
- Published: Oct. 26, 2023
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2023-46222
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.... Read more
- EPSS Score: %1.89
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45849
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner. ... Read more
Affected Products : helix_core- EPSS Score: %0.34
- Published: Nov. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45614
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successf... Read more
- EPSS Score: %0.87
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44350
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.... Read more
Affected Products : coldfusion- EPSS Score: %61.89
- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41419
An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.... Read more
Affected Products : gevent- EPSS Score: %2.63
- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41361
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.... Read more
- EPSS Score: %0.50
- Published: Aug. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41101
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and t... Read more
Affected Products : opennds- EPSS Score: %4.09
- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39143
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).... Read more
- EPSS Score: %88.63
- Published: Aug. 04, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-38545
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that ho... Read more
Affected Products : fedora curl windows_server_2019 active_iq_unified_manager oncommand_insight oncommand_workflow_automation libcurl windows_10_1809 windows_10_21h2 windows_10_22h2 +4 more products- EPSS Score: %22.22
- Published: Oct. 18, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2024-5989
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.... Read more
- Published: Jun. 25, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34039
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the ... Read more
Affected Products : aria_operations_for_networks- EPSS Score: %93.25
- Published: Aug. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32056
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability... Read more
- EPSS Score: %0.84
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32015
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +6 more products- EPSS Score: %2.72
- Published: Jun. 14, 2023
- Modified: Apr. 08, 2025