Latest CVE Feed
-
9.8
CRITICALCVE-2025-2538
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.... Read more
Affected Products : portal_for_arcgis- Published: Mar. 20, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-56521
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.... Read more
Affected Products : tcpdf- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2016-10253
An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordina... Read more
Affected Products : erlang\/otp- EPSS Score: %0.51
- Published: Mar. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10711
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.... Read more
- EPSS Score: %0.80
- Published: Jan. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2403
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.... Read more
Affected Products : symfony- EPSS Score: %0.15
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5280
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectiona... Read more
- EPSS Score: %1.71
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5773
php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of se... Read more
Affected Products : php- EPSS Score: %10.20
- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7411
ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that referen... Read more
Affected Products : php- EPSS Score: %0.76
- Published: Sep. 17, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7446
Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.... Read more
- EPSS Score: %2.02
- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7167
Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-b... Read more
- EPSS Score: %2.46
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7943
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.... Read more
- EPSS Score: %4.71
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-2794
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.... Read more
Affected Products : dotnetnuke- EPSS Score: %92.01
- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7954
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.... Read more
Affected Products : bundler- EPSS Score: %1.22
- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-9361
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series ... Read more
Affected Products : nport_5110_firmware nport_5100_series_firmware nport_5200_series_firmware nport_5400_series_firmware nport_5600_series_firmware nport_5100a_series_firmware nport_p5150a_series_firmware nport_5200a_series_firmware nport_5x50a1-m12_series_firmware nport_5600-8-dtl_series_firmware +42 more products- EPSS Score: %50.81
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9635
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip c... Read more
- EPSS Score: %20.46
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9935
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty boolean... Read more
Affected Products : php- EPSS Score: %2.32
- Published: Jan. 04, 2017
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-12940
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.... Read more
Affected Products : unrar- EPSS Score: %0.45
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13008
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().... Read more
Affected Products : tcpdump- EPSS Score: %1.12
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13019
The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print().... Read more
Affected Products : tcpdump- EPSS Score: %1.36
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13139
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.... Read more
- EPSS Score: %0.95
- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025