Latest CVE Feed
-
9.8
CRITICALCVE-2020-17353
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.... Read more
- Published: Aug. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17086
Raw Image Extension Remote Code Execution Vulnerability... Read more
Affected Products : raw_image_extension- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17078
Raw Image Extension Remote Code Execution Vulnerability... Read more
Affected Products : raw_image_extension- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16846
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.... Read more
- Actively Exploited
- Published: Nov. 06, 2020
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2007-6762
In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[] array.... Read more
Affected Products : linux_kernel- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2008-0081
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerabilit... Read more
- Published: Jan. 16, 2008
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2014-6440
VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-16629
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.... Read more
Affected Products : phpok- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-3504
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to A... Read more
Affected Products : jdeveloper- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-3737
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.... Read more
Affected Products : jboss_operations_network- Published: Aug. 02, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4607
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have ... Read more
- Published: Jul. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2020-16279
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.... Read more
Affected Products : rangeeos- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-1933
SQL injection vulnerability in Jifty::DBI before 0.68.... Read more
Affected Products : \- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16245
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.... Read more
Affected Products : iview- Published: Aug. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-1935
pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remote attackers to send arbitrary data while avoiding detection via crafted packets.... Read more
Affected Products : libpcap- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7983
The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8512
A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16226
Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.... Read more
- Published: Oct. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9366
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series ... Read more
Affected Products : nport_5110_firmware nport_5100_series_firmware nport_5200_series_firmware nport_5400_series_firmware nport_5600_series_firmware nport_5100a_series_firmware nport_p5150a_series_firmware nport_5200a_series_firmware nport_5x50a1-m12_series_firmware nport_5600-8-dtl_series_firmware +42 more products- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9849
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9... Read more
Affected Products : phpmyadmin- Published: Dec. 11, 2016
- Modified: Apr. 12, 2025