Latest CVE Feed
-
9.8
CRITICALCVE-2024-25912
Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. ... Read more
Affected Products : moveto- Published: Apr. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25412
com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.... Read more
- Published: Sep. 16, 2020
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2024-25845
In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.... Read more
- Published: Mar. 08, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-25843
In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.... Read more
Affected Products : import\/update_bulk_product- Published: Feb. 27, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2020-27507
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.... Read more
Affected Products : kamailio- Published: Mar. 15, 2023
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2024-25849
In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .... Read more
Affected Products : make_an_offer\/offer_your_price- Published: Mar. 08, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-27481
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Param... Read more
Affected Products : good_learning_management_system- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27422
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.... Read more
Affected Products : time_tracker- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27416
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.... Read more
Affected Products : mahavitaran- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27372
A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.... Read more
Affected Products : brandy- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25714
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has c... Read more
- Published: Feb. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-5027
Collabtive 1.0 has incorrect access control... Read more
Affected Products : collabtive- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4982
AVTECH AVN801 DVR has a security bypass via the administration login captcha... Read more
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38429
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.... Read more
Affected Products : linux_kernel- Published: Jul. 18, 2023
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2024-25678
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.... Read more
Affected Products : lsquic- Published: Feb. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2020-27297
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).... Read more
Affected Products : opc_ua_tunneller- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21652
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to eff... Read more
- Published: Mar. 18, 2024
- Modified: Jan. 09, 2025
-
9.8
CRITICALCVE-2024-49195
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair... Read more
- Published: Oct. 15, 2024
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2013-4743
Static HTTP Server 1.0 has a Local Overflow... Read more
Affected Products : static_http_server- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27251
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution.... Read more
Affected Products : factorytalk_linx- Published: Nov. 26, 2020
- Modified: Nov. 21, 2024