Latest CVE Feed
-
9.8
CRITICALCVE-2023-29542
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firef... Read more
- EPSS Score: %0.12
- Published: Jun. 19, 2023
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2023-36049
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 .net_framework windows_server_2019 visual_studio windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 +7 more products- EPSS Score: %2.21
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31870
An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow.... Read more
- EPSS Score: %1.28
- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38427
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.... Read more
- EPSS Score: %0.09
- Published: Jul. 18, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-38074
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability... Read more
- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9841
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."... Read more
- EPSS Score: %1.09
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-54661
readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.... Read more
Affected Products : socat- Published: Dec. 04, 2024
- Modified: Jan. 07, 2025
-
9.8
CRITICALCVE-2016-7447
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.... Read more
- EPSS Score: %2.03
- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-31199
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the unde... Read more
Affected Products : auditor- Actively Exploited
- EPSS Score: %4.32
- Published: Nov. 08, 2022
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2022-26612
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. ... Read more
- EPSS Score: %0.18
- Published: Apr. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32224
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ab... Read more
- EPSS Score: %1.52
- Published: Dec. 05, 2022
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2018-1117
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where... Read more
- EPSS Score: %0.20
- Published: Jun. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25117
php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, which might leads to RCE on PHP < 8.0, and doesn't validate if external refe... Read more
- Published: Feb. 21, 2024
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2021-21692
FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of 'delete'.... Read more
Affected Products : jenkins- EPSS Score: %0.61
- Published: Nov. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7584
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subse... Read more
- EPSS Score: %76.42
- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34423
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for... Read more
- EPSS Score: %1.60
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-21587
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network ... Read more
- Actively Exploited
- EPSS Score: %94.39
- Published: Oct. 18, 2022
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2021-34813
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution mig... Read more
Affected Products : olm- EPSS Score: %4.46
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9355
danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.... Read more
- EPSS Score: %0.53
- Published: Feb. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12026
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could resul... Read more
- EPSS Score: %1.18
- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024