Latest CVE Feed
-
9.8
CRITICALCVE-2020-17752
Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc8328952BA951AbE, an implementation for MillionCoin (MON).... Read more
Affected Products : mon- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-18185
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.... Read more
Affected Products : pluxml- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17510
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.... Read more
- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17479
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.... Read more
Affected Products : json_pattern_validator- Published: Aug. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1015
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.... Read more
- Published: Jan. 29, 2024
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2020-17463
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.... Read more
Affected Products : fuel_cms- Actively Exploited
- Published: Aug. 13, 2020
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2020-17438
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset v... Read more
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-2936
Elgg through 1.7.10 has a SQL injection vulnerability... Read more
Affected Products : elgg- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17496
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.... Read more
Affected Products : vbulletin- Actively Exploited
- Published: Aug. 12, 2020
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2017-5404
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, ... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17529
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impact... Read more
Affected Products : nuttx- Published: Dec. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17353
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.... Read more
- Published: Aug. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17086
Raw Image Extension Remote Code Execution Vulnerability... Read more
Affected Products : raw_image_extension- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17078
Raw Image Extension Remote Code Execution Vulnerability... Read more
Affected Products : raw_image_extension- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16846
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.... Read more
- Actively Exploited
- Published: Nov. 06, 2020
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2007-6762
In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[] array.... Read more
Affected Products : linux_kernel- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2008-0081
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerabilit... Read more
- Published: Jan. 16, 2008
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2014-6440
VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-16629
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.... Read more
Affected Products : phpok- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-3504
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to A... Read more
Affected Products : jdeveloper- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025