Latest CVE Feed
-
9.8
CRITICALCVE-2018-5147
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5122
A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-of-bounds write. This vulnerability affects Firefox < 58.... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5103
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3548
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack. ... Read more
- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8014
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will ... Read more
- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-4160
A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component LS Command Handler. The manipulation leads to buffer overflow. The attack may be launched remot... Read more
- Published: May. 01, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-3454
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.... Read more
- Published: Apr. 04, 2024
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-3460
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.... Read more
Affected Products : ultimate_member- Published: Jul. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3688
A vulnerability classified as critical has been found in Bylancer QuickJob 6.1. Affected is an unknown function of the component GET Parameter Handler. The manipulation of the argument keywords/gender leads to sql injection. It is possible to launch the a... Read more
Affected Products : quickjob- Published: Jul. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3435
The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.... Read more
Affected Products : user_activity_log- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3368
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3522
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal System allows SQL Injection.This issue affects License Portal System: before 1.48. ... Read more
Affected Products : license_portal_system- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3346
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially... Read more
Affected Products : c80_firmware e70_firmware e80_firmware m70v_firmware m720vs_firmware m720vs_15-type_firmware m720vw_firmware m730vs_firmware m730vs_15-type_firmware m730vw_firmware +32 more products- Published: Aug. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary... Read more
- Actively Exploited
- Published: Feb. 06, 2018
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-3326
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned... Read more
Affected Products : freebsd- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3264
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can lever... Read more
- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3243
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB ... Read more
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3265
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An u... Read more
Affected Products : powerpanel_server- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3224
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.... Read more
Affected Products : nuxt- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3094
A vulnerability classified as critical has been found in code-projects Agro-School Management System 1.0. Affected is the function doUpdateQuestion of the file btn_functions.php. The manipulation of the argument question_id leads to sql injection. It is p... Read more
Affected Products : agro-school_management_system- Published: Jun. 04, 2023
- Modified: Nov. 21, 2024