Latest CVE Feed
-
9.8
CRITICALCVE-2017-14064
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning a po... Read more
- EPSS Score: %1.94
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-24030
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse.... Read more
Affected Products : qualiex- EPSS Score: %1.42
- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24007
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.... Read more
Affected Products : human_resources- EPSS Score: %1.85
- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23980
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.... Read more
Affected Products : conference_management- EPSS Score: %0.48
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23979
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.... Read more
Affected Products : 13enforme_cms- EPSS Score: %0.25
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24203
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.... Read more
- EPSS Score: %5.69
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23618
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root. ... Read more
- EPSS Score: %0.27
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23973
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.... Read more
Affected Products : kandnconcepts_club_cms- EPSS Score: %0.25
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1265
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information ... Read more
- EPSS Score: %1.00
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-23606
An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious... Read more
- Published: Feb. 20, 2024
- Modified: Aug. 10, 2025
-
9.8
CRITICALCVE-2020-23878
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.... Read more
Affected Products : pdf2json- EPSS Score: %0.46
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15101
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.... Read more
- EPSS Score: %0.32
- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23828
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack us... Read more
Affected Products : online_course_registration- EPSS Score: %2.31
- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23625
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root. ... Read more
- EPSS Score: %10.01
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23763
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.... Read more
Affected Products : online_book_store- EPSS Score: %0.91
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23679
Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.... Read more
Affected Products : linux_network_project- EPSS Score: %1.18
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5645
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.... Read more
- EPSS Score: %94.01
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-23685
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.... Read more
Affected Products : 188jianzhan- EPSS Score: %0.58
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23653
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.... Read more
Affected Products : thinkadmin- EPSS Score: %12.69
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23486
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.... Read more
- Published: Apr. 15, 2024
- Modified: Jun. 30, 2025