Latest CVE Feed
-
9.8
CRITICALCVE-2018-13797
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.... Read more
Affected Products : node-macaddress- EPSS Score: %11.81
- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11210
TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2... Read more
Affected Products : tinyxml2- EPSS Score: %0.48
- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10562
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the us... Read more
- Actively Exploited
- EPSS Score: %94.03
- Published: May. 04, 2018
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2018-10561
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. ... Read more
- Actively Exploited
- EPSS Score: %92.18
- Published: May. 04, 2018
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2018-1000875
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to a... Read more
- EPSS Score: %0.39
- Published: Dec. 20, 2018
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2017-20146
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.... Read more
Affected Products : handlers- EPSS Score: %0.06
- Published: Dec. 27, 2022
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2017-1000486
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution... Read more
Affected Products : primefaces- Actively Exploited
- EPSS Score: %93.82
- Published: Jan. 03, 2018
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2019-8272
UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.... Read more
- EPSS Score: %1.49
- Published: Mar. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8258
UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.... Read more
- EPSS Score: %4.59
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2009-4488
Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequenc... Read more
Affected Products : varnish- EPSS Score: %3.02
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2025-8031
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird... Read more
- Published: Jul. 22, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2022-24955
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.... Read more
- EPSS Score: %0.69
- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43782
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability ca... Read more
Affected Products : crowd- EPSS Score: %0.46
- Published: Nov. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-11120
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploite... Read more
Affected Products : gv-vs12_firmware gv-vs12 gv-vs11_firmware gv-vs11 gv-dsp_lpr_firmware gv-dsp_lpr gvlx_4_firmware gvlx_4- Actively Exploited
- Published: Nov. 15, 2024
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2025-1012
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2022-21445
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated a... Read more
- Actively Exploited
- EPSS Score: %89.99
- Published: Apr. 19, 2022
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2019-10160
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abus... Read more
Affected Products : ubuntu_linux enterprise_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_tus +5 more products- EPSS Score: %1.81
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26723
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.... Read more
Affected Products : macos- EPSS Score: %1.22
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-32611
HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.... Read more
Affected Products : hdf5- Published: May. 14, 2024
- Modified: Apr. 18, 2025
-
9.8
CRITICALCVE-2022-37888
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successfu... Read more
Affected Products : arubaos instant scalance_w1750d_firmware scalance_w1750d ap-103 ap-114 ap-115 ap-120 ap-121 ap-130 +46 more products- EPSS Score: %1.47
- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024