Latest CVE Feed
-
9.8
CRITICALCVE-2019-15565
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.... Read more
Affected Products : icommktconnector- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15679
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.... Read more
Affected Products : tightvnc- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15551
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.... Read more
Affected Products : smallvec- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15567
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.... Read more
Affected Products : arena- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15556
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.... Read more
Affected Products : social_network- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15559
DianoxDragon Hawn before 2019-07-10 allows SQL injection.... Read more
Affected Products : hawn- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15534
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.... Read more
Affected Products : raml-module-builder- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15533
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.... Read more
Affected Products : xenfcoresharp- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15522
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.... Read more
Affected Products : csync2- Published: Mar. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15543
An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases.... Read more
Affected Products : slice-deque- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15490
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.... Read more
Affected Products : openitcockpit- Published: Aug. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15555
FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.... Read more
Affected Products : wellness- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2007-5775
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a... Read more
- Published: Nov. 01, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2024-44299
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-44241
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-38240
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability... Read more
Affected Products : windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 windows_11_22h2 +7 more products- Published: Sep. 10, 2024
- Modified: Sep. 17, 2024
-
9.8
CRITICALCVE-2024-31581
FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.... Read more
- Published: Apr. 17, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Jun. 11, 2024
- Modified: Sep. 15, 2025
-
9.8
CRITICALCVE-2024-25153
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to ... Read more
- Published: Mar. 13, 2024
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2024-21416
Windows TCP/IP Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 windows_11_22h2 windows windows_11_23h2 windows_server_2022_23h2 +2 more products- Published: Sep. 10, 2024
- Modified: Sep. 20, 2024