Latest CVE Feed
-
9.8
CRITICALCVE-2023-31212
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7,... Read more
Affected Products : database_for_contact_form_7\,_wpforms\,_elementor_forms- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31914
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31886
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versi... Read more
Affected Products : apogee_pxc_modular_firmware talon_tc_compact_firmware talon_tc_modular_firmware nucleus_net nucleus_readystart_v3 nucleus_source_code apogee_modular_building_controller_firmware apogee_modular_equiment_controller_firmware apogee_pxc_compact_firmware desigo_pxc00-e.d_firmware +38 more products- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31800
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achi... Read more
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with La... Read more
- Actively Exploited
- Published: Jan. 12, 2021
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2023-31062
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Bu... Read more
Affected Products : inlong- Published: May. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31047
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the la... Read more
- Published: May. 07, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-31039
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arb... Read more
Affected Products : brpc- Published: May. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31067
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.... Read more
Affected Products : tsplus_remote_access- Published: Sep. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31030
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code executio... Read more
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31029
NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability m... Read more
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-30820
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8. A remote attacker may be able to cause arbitrary code execution.... Read more
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30869
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.... Read more
- Published: May. 02, 2023
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2023-30945
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacke... Read more
- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30806
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/... Read more
Affected Products : next-gen_application_firewall- Published: Oct. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30803
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a ... Read more
Affected Products : next-gen_application_firewall- Published: Oct. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30801
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use t... Read more
Affected Products : qbittorrent- Published: Oct. 10, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-41957
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.... Read more
Affected Products : simple_membership- Published: May. 17, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2023-30967
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. ... Read more
Affected Products : orbital_simulator- Published: Oct. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30769
Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, send it to individual nodes and take them offline. An attacker can crawl the network peers using getaddr message and attack the unpatched... Read more
Affected Products : dogecoin- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024