Latest CVE Feed
-
9.8
CRITICALCVE-2019-2646
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attack... Read more
Affected Products : weblogic_server- EPSS Score: %2.02
- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-2729
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacke... Read more
- EPSS Score: %94.36
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14926
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being r... Read more
- EPSS Score: %0.36
- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15562
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm... Read more
Affected Products : gorm- EPSS Score: %0.54
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12699
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objd... Read more
- EPSS Score: %0.53
- Published: Jun. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-4197
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editi... Read more
- EPSS Score: %6.28
- Published: Nov. 06, 2010
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2019-16378
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.... Read more
- EPSS Score: %0.51
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25575
An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type confusion flaw when downcasting. NOTE: This vulnerability only affects products that are no longer supported... Read more
Affected Products : failure- EPSS Score: %0.62
- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-26972
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a... Read more
Affected Products : firefox- EPSS Score: %0.52
- Published: Jan. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8271
The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.... Read more
Affected Products : rtmpdump- EPSS Score: %0.64
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-28144
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the... Read more
- EPSS Score: %2.78
- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8805
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vect... Read more
- EPSS Score: %1.20
- Published: Feb. 23, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-2628
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was i... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation curl- EPSS Score: %0.88
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-3952
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.... Read more
Affected Products : vcenter_server- Actively Exploited
- EPSS Score: %93.32
- Published: Apr. 10, 2020
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2013-4976
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials... Read more
- EPSS Score: %9.35
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14349
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.... Read more
- EPSS Score: %1.34
- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11989
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.... Read more
Affected Products : shiro- EPSS Score: %76.01
- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-5257
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execut... Read more
- EPSS Score: %0.82
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5277
Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)... Read more
- EPSS Score: %1.36
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2020-6831
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.... Read more
- EPSS Score: %10.15
- Published: May. 26, 2020
- Modified: Nov. 21, 2024