Latest CVE Feed
-
9.8
CRITICALCVE-2024-11236
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.... Read more
Affected Products : php- Published: Nov. 24, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2020-14032
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.... Read more
Affected Products : box-r1000_firmware- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-11284
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the acco... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11258
A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can ... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2020-13963
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest ac... Read more
Affected Products : soplanning- Published: Mar. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13968
CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.... Read more
Affected Products : business_platform- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13957
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization... Read more
Affected Products : solr- Published: Oct. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-14001
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with t... Read more
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-14011
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled Deployments featu... Read more
Affected Products : lansweeper- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-7933
The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-13942
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is hi... Read more
Affected Products : unomi- Published: Nov. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13927
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default ... Read more
Affected Products : airflow- Actively Exploited
- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-11120
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploite... Read more
Affected Products : gv-vs12_firmware gv-vs12 gv-vs11_firmware gv-vs11 gv-dsp_lpr_firmware gv-dsp_lpr gvlx_4_firmware gvlx_4- Actively Exploited
- Published: Nov. 15, 2024
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2020-13919
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n,... Read more
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17031
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.... Read more
Affected Products : qts- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-13909
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix.... Read more
Affected Products : ignition- Published: Jun. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-11122
A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is some unknown functionality of the file /crm/wechatSession/index.php?msgid=1&operation=upload. The manipulation of the a... Read more
Affected Products : lingdang_crm- Published: Nov. 12, 2024
- Modified: Aug. 27, 2025
-
9.8
CRITICALCVE-2022-26708
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.... Read more
Affected Products : macos- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2009-4488
Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequenc... Read more
Affected Products : varnish- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-11068
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s acco... Read more
- Published: Nov. 11, 2024
- Modified: Nov. 24, 2024