Latest CVE Feed
-
9.8
CRITICALCVE-2023-32169
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerabi... Read more
Affected Products : d-view_8- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
9.8
CRITICAL- Published: Oct. 31, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-39890
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.... Read more
Affected Products : gitlab- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32074
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2 ... Read more
- Published: May. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38441
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.... Read more
Affected Products : cyclonedds- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32117
Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.... Read more
Affected Products : integrate_google_drive- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2021-38294
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to auth... Read more
Affected Products : storm- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38173
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.... Read more
- Published: Aug. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37931
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37929
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37928
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.... Read more
Affected Products : manageengine_admanager_plus- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37592
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.... Read more
Affected Products : suricata- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36365
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.... Read more
Affected Products : nagios_xi- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31985
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.... Read more
- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2018-3191
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attack... Read more
Affected Products : weblogic_server- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31986
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.... Read more
- Published: May. 15, 2023
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2021-3586
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to... Read more
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32015
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +6 more products- Published: Jun. 14, 2023
- Modified: Apr. 08, 2025
-
9.8
CRITICALCVE-2023-32014
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +6 more products- Published: Jun. 14, 2023
- Modified: Apr. 08, 2025
-
9.8
CRITICALCVE-2023-32002
The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x... Read more
Affected Products : node.js- Published: Aug. 21, 2023
- Modified: Jul. 02, 2025