Latest CVE Feed
-
9.8
CRITICALCVE-2024-48886
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManage... Read more
Affected Products : fortimanager fortios fortiproxy fortianalyzer fortianalyzer_cloud fortimanager_cloud- Published: Jan. 14, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-47606
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variable, wh... Read more
- Published: Dec. 12, 2024
- Modified: Apr. 19, 2025
-
9.8
CRITICALCVE-2024-47484
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote... Read more
- Published: Dec. 10, 2024
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2024-41874
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing c... Read more
Affected Products : coldfusion- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-3845
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Apr. 17, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-37341
Microsoft SQL Server Elevation of Privilege Vulnerability... Read more
- Published: Sep. 10, 2024
- Modified: Sep. 23, 2024
-
9.8
CRITICALCVE-2024-36080
Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.... Read more
Affected Products :- Published: May. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-32040
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.1... Read more
- Published: Apr. 22, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2024-30300
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive inform... Read more
Affected Products : framemaker_publishing_server- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-29943
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.... Read more
Affected Products : firefox- Published: Mar. 22, 2024
- Modified: Apr. 01, 2025
-
9.8
CRITICALCVE-2024-25714
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has c... Read more
- EPSS Score: %0.14
- Published: Feb. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25189
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.... Read more
Affected Products : jwt_c_library- EPSS Score: %0.06
- Published: Feb. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23606
An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious... Read more
- Published: Feb. 20, 2024
- Modified: Aug. 10, 2025
-
9.8
CRITICALCVE-2024-22051
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code e... Read more
- EPSS Score: %7.13
- Published: Jan. 04, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-13160
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : endpoint_manager- Actively Exploited
- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-11737
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.... Read more
Affected Products : modicon_m258_firmware modicon_m241_firmware modicon_m251_firmware modicon_lmc058_firmware- Published: Dec. 11, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2024-0321
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.... Read more
Affected Products : gpac- EPSS Score: %0.07
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5168
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating system... Read more
- EPSS Score: %0.26
- Published: Sep. 27, 2023
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2023-50711
vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starting in version 0.5.0 and prior to version 0.12.0, an issue in the `FamStructWrapper::deserialize` implementation provided by the crate f... Read more
Affected Products : vmm-sys-util- EPSS Score: %0.07
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49937
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.... Read more
Affected Products : slurm- EPSS Score: %0.26
- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024