Latest CVE Feed
-
9.8
CRITICALCVE-2023-28561
Memory corruption in QESL while processing payload from external ESL device to firmware.... Read more
- EPSS Score: %0.14
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28489
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Ope... Read more
- EPSS Score: %1.60
- Published: Apr. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1992
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges. T... Read more
- EPSS Score: %2.29
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40567
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `clear_decompress_bands_data` function in which there is no offset validation. Abuse o... Read more
- EPSS Score: %0.10
- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1944
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.... Read more
- EPSS Score: %0.70
- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28462
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the se... Read more
- EPSS Score: %1.34
- Published: Mar. 30, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-28562
Memory corruption while handling payloads from remote ESL.... Read more
Affected Products : aqt1000_firmware qca6391_firmware qca6420_firmware qca6430_firmware sd855_firmware wcd9341_firmware wcd9380_firmware wcd9385_firmware wcn3980_firmware wcn3988_firmware +126 more products- EPSS Score: %0.08
- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1654
On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) Continued processing of this malformed HTTP ... Read more
Affected Products : junos- EPSS Score: %2.13
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28398
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without pro... Read more
- EPSS Score: %0.03
- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28379
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerabili... Read more
- EPSS Score: %0.22
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28408
Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.... Read more
Affected Products : mw_wp_form- EPSS Score: %2.80
- Published: May. 23, 2023
- Modified: Jan. 17, 2025
-
9.8
CRITICALCVE-2023-28354
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pa... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-28343
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.... Read more
- EPSS Score: %94.17
- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15208
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension ... Read more
- EPSS Score: %0.33
- Published: Sep. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-14938
An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size verification, leading to a heap-based buffer overflow.... Read more
Affected Products : freedroidrpg- EPSS Score: %0.60
- Published: Jun. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-14687
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with networ... Read more
Affected Products : weblogic_server- EPSS Score: %1.90
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28081
A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where ... Read more
Affected Products : hermes- EPSS Score: %0.41
- Published: May. 18, 2023
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2023-27992
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticat... Read more
- Actively Exploited
- EPSS Score: %86.39
- Published: Jun. 19, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2017-16398
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vul... Read more
- EPSS Score: %4.62
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-27846
SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, ... Read more
Affected Products : theme_volty_cms_blog- EPSS Score: %0.29
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024