Latest CVE Feed
-
9.8
CRITICALCVE-2009-1151
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.... Read more
- Actively Exploited
- EPSS Score: %93.03
- Published: Mar. 26, 2009
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-5806
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.... Read more
Affected Products : moveit_transfer- Published: Jun. 25, 2024
- Modified: Jan. 16, 2025
-
9.8
CRITICALCVE-2023-32728
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.... Read more
- EPSS Score: %0.53
- Published: Dec. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8387
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8785
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.... Read more
Affected Products : whatsup_gold- Published: Dec. 02, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2024-5660
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Ne... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2019-8042
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exp... Read more
- EPSS Score: %39.72
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34416
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulne... Read more
- EPSS Score: %0.31
- Published: Jun. 19, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2021-27649
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %1.46
- Published: Jun. 23, 2021
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2021-27860
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory id... Read more
- Actively Exploited
- EPSS Score: %42.72
- Published: Dec. 08, 2021
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2019-8205
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation... Read more
- EPSS Score: %4.12
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12899
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus tcpdump- EPSS Score: %2.06
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2025-21298
Windows OLE Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Jan. 14, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-3566
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.... Read more
- Published: Apr. 10, 2024
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2025-30465
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-3847
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Apr. 17, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-43360
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.... Read more
Affected Products : zoneminder- Published: Aug. 12, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.... Read more
Affected Products : webpanel- Actively Exploited
- EPSS Score: %94.33
- Published: Jan. 05, 2023
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2024-36031
In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a probl... Read more
Affected Products : linux_kernel- Published: May. 30, 2024
- Modified: Apr. 01, 2025
-
9.8
CRITICALCVE-2024-7530
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.... Read more
Affected Products : firefox- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024