Latest CVE Feed
-
9.8
CRITICALCVE-2017-5438
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR ... Read more
- EPSS Score: %2.02
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23534
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.... Read more
Affected Products : masterlab- EPSS Score: %0.32
- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23286
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. Proc... Read more
- Published: Mar. 08, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2017-6889
An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.... Read more
Affected Products : libraw-demosaic-pack-gpl2- EPSS Score: %0.44
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-23321
There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.... Read more
Affected Products : jerryscript- EPSS Score: %0.36
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23265
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. An... Read more
- Published: Mar. 08, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2018-12407
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.... Read more
- EPSS Score: %4.61
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-1378
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.... Read more
- EPSS Score: %0.23
- Published: Nov. 15, 2010
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2020-23302
There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0... Read more
Affected Products : jerryscript- EPSS Score: %0.36
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10878
In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and related functions in engine/shared/datafile.cpp that can lead to an arbitrary free and out-of-bounds pointer write, possibly resulting ... Read more
Affected Products : teeworlds- EPSS Score: %2.66
- Published: Apr. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23306
There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.... Read more
Affected Products : jerryscript- EPSS Score: %0.38
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28613
SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.... Read more
Affected Products : php_task_management_system- Published: Apr. 24, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2020-23448
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.... Read more
Affected Products : newbee-mall- EPSS Score: %0.40
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12751
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally... Read more
- EPSS Score: %0.76
- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15715
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeti... Read more
Affected Products : zoom- EPSS Score: %1.51
- Published: Nov. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23037
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.... Read more
Affected Products : playable- EPSS Score: %0.51
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6125
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.... Read more
Affected Products : chicken- EPSS Score: %0.64
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14540
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.... Read more
- EPSS Score: %7.98
- Published: Sep. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23113
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 th... Read more
- Actively Exploited
- EPSS Score: %45.02
- Published: Feb. 15, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2018-18249
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navi... Read more
Affected Products : icinga_web_2- EPSS Score: %0.51
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024