Latest CVE Feed
-
9.8
CRITICALCVE-2024-38199
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Aug. 13, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2024-3930
In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.... Read more
Affected Products : akana_api- Published: Jul. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-2771
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.... Read more
Affected Products : ffmpeg- EPSS Score: %0.41
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2012-2714
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.... Read more
Affected Products : browserid- EPSS Score: %6.66
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28009
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF12... Read more
Affected Products :- Published: Mar. 28, 2024
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2012-2773
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.... Read more
Affected Products : ffmpeg- EPSS Score: %0.41
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-45491
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).... Read more
Affected Products : libexpat- Published: Aug. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-2666
golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.... Read more
Affected Products : go- EPSS Score: %0.51
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-20184
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.... Read more
Affected Products : gateone- EPSS Score: %6.44
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2009-1151
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.... Read more
- Actively Exploited
- EPSS Score: %93.03
- Published: Mar. 26, 2009
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-5806
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.... Read more
Affected Products : moveit_transfer- Published: Jun. 25, 2024
- Modified: Jan. 16, 2025
-
9.8
CRITICALCVE-2020-20120
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.... Read more
Affected Products : thinkphp- EPSS Score: %1.11
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32728
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.... Read more
- EPSS Score: %0.53
- Published: Dec. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-2226
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.... Read more
Affected Products : invision_power_board- EPSS Score: %13.03
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8785
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.... Read more
Affected Products : whatsup_gold- Published: Dec. 02, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2020-20092
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.... Read more
Affected Products : articlecms- EPSS Score: %0.43
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5660
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Ne... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2019-8042
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exp... Read more
- EPSS Score: %39.72
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1959
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation ... Read more
Affected Products : syncope- EPSS Score: %1.65
- Published: May. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1957
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.... Read more
- EPSS Score: %79.79
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024