Latest CVE Feed
-
9.8
CRITICALCVE-2019-3568
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior... Read more
- Actively Exploited
- EPSS Score: %36.03
- Published: May. 14, 2019
- Modified: Sep. 03, 2025
-
9.8
CRITICALCVE-2019-3463
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.... Read more
- EPSS Score: %8.56
- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-2904
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
- EPSS Score: %21.04
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-2729
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacke... Read more
- EPSS Score: %94.36
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-2658
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
Affected Products : weblogic_server- EPSS Score: %2.02
- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-1999-1324
VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force pass... Read more
Affected Products : openvms_vax- EPSS Score: %1.01
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with netwo... Read more
- Actively Exploited
- EPSS Score: %94.47
- Published: Apr. 26, 2019
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2019-2279
Shared memory gets updated with invalid data and may lead to access beyond the allocated memory. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Weara... Read more
Affected Products : qca6574au_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9150_firmware qcs605_firmware +66 more products- EPSS Score: %0.32
- Published: Jul. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-1999-0199
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaw... Read more
Affected Products : glibc- EPSS Score: %0.68
- Published: Oct. 06, 2020
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2020-10655
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with lo... Read more
Affected Products : insider_threat_management_server- EPSS Score: %6.60
- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-2030
In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: A... Read more
Affected Products : android- EPSS Score: %0.89
- Published: Apr. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-25217
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on the switch_php fu... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2019-25159
A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This affects an unknown part of the file config/cargos.php. The manipulation of the argument dni_profe leads to sql injection. Upgrading to... Read more
Affected Products : intranet_del_monterroso- EPSS Score: %0.05
- Published: Feb. 04, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26793
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.... Read more
Affected Products : libmodbus- Published: May. 01, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2019-25224
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.... Read more
Affected Products : wp_database_backup- Published: Jul. 25, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-0803
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.... Read more
Affected Products :- Published: Mar. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0808
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)... Read more
- EPSS Score: %0.34
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-0794
Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering fonts embedded in a PDF file.... Read more
Affected Products :- Published: Feb. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-25141
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possibl... Read more
Affected Products : easy_wp_smtp- EPSS Score: %63.24
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12951
An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.... Read more
Affected Products : mongoose- EPSS Score: %0.46
- Published: Jun. 24, 2019
- Modified: Nov. 21, 2024