Latest CVE Feed
-
9.8
CRITICALCVE-2012-1622
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : ofbiz- EPSS Score: %6.48
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0899
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.... Read more
- EPSS Score: %9.67
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9852
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.... Read more
- EPSS Score: %1.32
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10984
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.... Read more
Affected Products : freeradius- EPSS Score: %27.81
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11139
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.... Read more
- EPSS Score: %0.47
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12065
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.... Read more
Affected Products : cacti- EPSS Score: %3.32
- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7705
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.... Read more
Affected Products : data_ontap oncommand_performance_manager oncommand_unified_manager ntp xenserver clustered_data_ontap simatic_cp_443-1_opc_ua_firmware tim_4r-ie_firmware tim_4r-ie_dnp3_firmware tim_4r-ie +1 more products- EPSS Score: %29.58
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2011-1517
SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.... Read more
Affected Products : netweaver- EPSS Score: %2.37
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12987
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus tcpdump- EPSS Score: %2.06
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13012
The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().... Read more
Affected Products : tcpdump- EPSS Score: %1.12
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13046
The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().... Read more
Affected Products : tcpdump- EPSS Score: %0.60
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13687
The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().... Read more
- EPSS Score: %2.06
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13889
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.... Read more
- EPSS Score: %0.41
- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-1460
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.... Read more
- EPSS Score: %0.28
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15917
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.... Read more
- EPSS Score: %2.24
- Published: Jul. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15893
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP ... Read more
- EPSS Score: %84.78
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15900
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and coul... Read more
- EPSS Score: %11.70
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15906
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.... Read more
- EPSS Score: %91.14
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15921
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.... Read more
Affected Products : eframework- EPSS Score: %18.99
- Published: Jul. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15851
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible ... Read more
Affected Products : backup_\&_replication_transporter- EPSS Score: %1.04
- Published: Sep. 24, 2020
- Modified: Nov. 21, 2024