Latest CVE Feed
-
9.8
CRITICALCVE-2021-20314
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.... Read more
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8199
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lea... Read more
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14670
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.... Read more
- Published: Aug. 15, 2019
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2011-4183
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.... Read more
Affected Products : open_build_service- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-1468
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain una... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4069
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.... Read more
Affected Products : packetfence- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4068
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password.... Read more
Affected Products : packetfence- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19853
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.... Read more
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20815
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.... Read more
Affected Products : qemu- Published: May. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19596
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.... Read more
Affected Products : core_ftp- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19625
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.... Read more
Affected Products : gridx- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19672
Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, bypass the getimagesize function, upload php file, getshell.... Read more
Affected Products : niushop- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19510
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.... Read more
- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1344
Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of 'LOF_service.exe' and 'LaborOfficeFree.exe' located in the '%programfiles(x... Read more
Affected Products : laborofficefree- Published: Feb. 19, 2024
- Modified: Mar. 24, 2025
-
9.8
CRITICALCVE-2024-1351
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections ... Read more
- Published: Mar. 07, 2024
- Modified: Mar. 11, 2025
-
9.8
CRITICALCVE-2020-19305
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.... Read more
Affected Products : metinfo- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12989
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.... Read more
- Actively Exploited
- Published: Jul. 16, 2019
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2020-19301
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.... Read more
Affected Products : vaethink- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19302
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".... Read more
Affected Products : vaethink- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024