Latest CVE Feed
-
9.8
CRITICALCVE-2022-26871
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.... Read more
- Actively Exploited
- Published: Mar. 29, 2022
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2020-14750
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthent... Read more
- Actively Exploited
- Published: Nov. 02, 2020
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2023-33273
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).... Read more
Affected Products : monitoring- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2660
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine. ... Read more
Affected Products : dialink- Published: Dec. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26258
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.... Read more
- Actively Exploited
- Published: Mar. 28, 2022
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2022-25643
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.... Read more
Affected Products : seatd- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33082
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.... Read more
Affected Products : qca6391_firmware wcd9380_firmware wcd9385_firmware wcn3980_firmware ar8035_firmware ar9380_firmware csr8811_firmware wcn685x-5_firmware wcn685x-1_firmware wcn785x-1_firmware +220 more products- Published: Dec. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-0269
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.... Read more
Affected Products : gnuboard- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2022-24838
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inje... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24791
Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are not explicitly enabling ep... Read more
Affected Products : wasmtime- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32956
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to execute arbitrary code via unspecifi... Read more
Affected Products : router_manager- Published: May. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33009
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)... Read more
Affected Products : usg20-vpn_firmware usg_40_firmware usg_40w_firmware usg_60_firmware usg_60w_firmware usg_20w-vpn_firmware usg_flex_100_firmware usg_flex_100w_firmware usg_flex_200_firmware usg_flex_50_firmware +36 more products- Actively Exploited
- Published: May. 24, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2024-35305
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.... Read more
- Published: Jun. 10, 2024
- Modified: Sep. 16, 2025
-
9.8
CRITICALCVE-2022-24300
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.... Read more
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24065
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flag... Read more
- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23901
A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.... Read more
Affected Products : re2c- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23131
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to ... Read more
- Actively Exploited
- Published: Jan. 13, 2022
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2022-23086
Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with acc... Read more
Affected Products : freebsd- Published: Feb. 15, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2022-22956
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the au... Read more
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-0199
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculat... Read more
Affected Products : ngircd- Published: May. 02, 2005
- Modified: Apr. 03, 2025