Latest CVE Feed
-
9.8
CRITICALCVE-2020-24336
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the answer's length is sane. Therefore, when copying an address of an arbitrar... Read more
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-11636
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.... Read more
Affected Products : graphicsmagick- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10965
An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.... Read more
Affected Products : irssi- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-28991
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.... Read more
Affected Products : gitea- Published: Nov. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8009
The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote registered ... Read more
Affected Products : mediawiki- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-24217
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly... Read more
- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12627
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.... Read more
Affected Products : xerces-c\+\+- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24214
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main ... Read more
- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12791
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.... Read more
Affected Products : salt- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12988
The telnet parser in tcpdump before 4.9.2 has a buffer over-read in print-telnet.c:telnet_parse().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13005
The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:xid_map_enter().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-24074
The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.... Read more
Affected Products : silk-v3-decoder- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14064
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning a po... Read more
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-24030
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse.... Read more
Affected Products : qualiex- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24007
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.... Read more
Affected Products : human_resources- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23980
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.... Read more
Affected Products : conference_management- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23979
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.... Read more
Affected Products : 13enforme_cms- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24203
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.... Read more
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23618
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root. ... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23973
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.... Read more
Affected Products : kandnconcepts_club_cms- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024