Latest CVE Feed
-
9.8
CRITICALCVE-2022-39237
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital s... Read more
Affected Products : singularity_image_format- EPSS Score: %0.06
- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25283
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.... Read more
- EPSS Score: %7.44
- Published: Feb. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22282
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.... Read more
Affected Products : sma1000_firmware sma_6200_firmware sma_6210_firmware sma_7200_firmware sma_7210_firmware sma_8000v_firmware sma_6200 sma_6210 sma_7200 sma_7210 +1 more products- EPSS Score: %0.36
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.... Read more
- EPSS Score: %0.31
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2009-1151
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.... Read more
- Actively Exploited
- EPSS Score: %93.03
- Published: Mar. 26, 2009
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-5806
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.... Read more
Affected Products : moveit_transfer- Published: Jun. 25, 2024
- Modified: Jan. 16, 2025
-
9.8
CRITICALCVE-2023-32728
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.... Read more
- EPSS Score: %0.53
- Published: Dec. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8387
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8785
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.... Read more
Affected Products : whatsup_gold- Published: Dec. 02, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2024-5660
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Ne... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2019-8042
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exp... Read more
- EPSS Score: %39.72
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34416
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulne... Read more
- EPSS Score: %0.31
- Published: Jun. 19, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2021-27649
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %1.46
- Published: Jun. 23, 2021
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2021-27860
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory id... Read more
- Actively Exploited
- EPSS Score: %42.72
- Published: Dec. 08, 2021
- Modified: Apr. 02, 2025
-
9.8
CRITICALCVE-2019-8205
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation... Read more
- EPSS Score: %4.12
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12899
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus tcpdump- EPSS Score: %2.06
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2025-21298
Windows OLE Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Jan. 14, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-3566
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.... Read more
- Published: Apr. 10, 2024
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2025-30465
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-3847
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Apr. 17, 2024
- Modified: Dec. 19, 2024