Latest CVE Feed
-
9.8
CRITICALCVE-2020-25506
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.... Read more
- Actively Exploited
- EPSS Score: %93.86
- Published: Feb. 02, 2021
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2023-28731
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Jooml... Read more
Affected Products : acymailing- EPSS Score: %2.07
- Published: Mar. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-2506
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This... Read more
Affected Products : helpdesk- Actively Exploited
- EPSS Score: %31.57
- Published: Feb. 03, 2021
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2020-24978
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.... Read more
Affected Products : netwide_assembler- EPSS Score: %0.41
- Published: Sep. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28614
Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page.... Read more
Affected Products : smart_trade- EPSS Score: %3.16
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28611
Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.... Read more
- EPSS Score: %0.10
- Published: Mar. 23, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2020-24027
In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.... Read more
Affected Products : liblivemedia- EPSS Score: %0.55
- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22669
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection ... Read more
- EPSS Score: %0.07
- Published: Sep. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22083
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing ar... Read more
Affected Products : jsonpickle- EPSS Score: %4.67
- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40569
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `progressive_decompress` function. This issue is likely down to incorrect calculations... Read more
- EPSS Score: %0.10
- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14201
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.... Read more
Affected Products : u-boot- EPSS Score: %0.44
- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40574
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `writePixelBGRX` function. This issue is likely down to incorrect calculations of the ... Read more
Affected Products : freerdp- EPSS Score: %0.12
- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28561
Memory corruption in QESL while processing payload from external ESL device to firmware.... Read more
- EPSS Score: %0.14
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28489
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Ope... Read more
- EPSS Score: %1.60
- Published: Apr. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1992
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges. T... Read more
- EPSS Score: %2.29
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40567
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `clear_decompress_bands_data` function in which there is no offset validation. Abuse o... Read more
- EPSS Score: %0.10
- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1944
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.... Read more
- EPSS Score: %0.70
- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28462
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the se... Read more
- EPSS Score: %1.34
- Published: Mar. 30, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-28562
Memory corruption while handling payloads from remote ESL.... Read more
Affected Products : aqt1000_firmware qca6391_firmware qca6420_firmware qca6430_firmware sd855_firmware wcd9341_firmware wcd9380_firmware wcd9385_firmware wcn3980_firmware wcn3988_firmware +126 more products- EPSS Score: %0.08
- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1654
On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) Continued processing of this malformed HTTP ... Read more
Affected Products : junos- EPSS Score: %2.13
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024