Latest CVE Feed
-
9.8
CRITICALCVE-2019-14943
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.... Read more
Affected Products : gitlab- EPSS Score: %0.30
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25823
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `sh... Read more
Affected Products : gradio- EPSS Score: %0.09
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-1373
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.... Read more
Affected Products : exchange_server- EPSS Score: %12.50
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13451
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.... Read more
- EPSS Score: %0.96
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25770
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning. ... Read more
- EPSS Score: %0.05
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2004-0847
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation... Read more
- EPSS Score: %64.44
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-25775
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.... Read more
Affected Products : ethernet_controller_rdma_driver_for_linux- EPSS Score: %0.22
- Published: Aug. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28115
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` fun... Read more
Affected Products : snappy- EPSS Score: %19.85
- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25736
An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.... Read more
Affected Products : firefox- EPSS Score: %0.38
- Published: Jun. 19, 2023
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2023-25699
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: fr... Read more
- Published: Apr. 03, 2024
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2023-25690
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specif... Read more
Affected Products : http_server- EPSS Score: %69.02
- Published: Mar. 07, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-25668
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlo... Read more
Affected Products : tensorflow- EPSS Score: %1.50
- Published: Mar. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11634
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.... Read more
- Actively Exploited
- EPSS Score: %56.20
- Published: May. 22, 2019
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2023-25664
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1. ... Read more
Affected Products : tensorflow- EPSS Score: %0.08
- Published: Mar. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25610
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 throug... Read more
Affected Products : fortimanager fortios fortiswitchmanager fortiproxy fortiweb fortianalyzer fortiswitch fortios-6k7k fortianalyzer- Published: Mar. 24, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2019-11131
Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.... Read more
Affected Products : active_management_technology_firmware- EPSS Score: %0.59
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10945
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.... Read more
- EPSS Score: %85.38
- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10694
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resol... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.42
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10202
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML ja... Read more
- EPSS Score: %1.83
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25657
Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7 are impacted by a remote code execution vulnerability. Nautobot did not properly sandbox Jinja2 template rendering. In Nautobot 1.5.7 ... Read more
Affected Products : nautobot- EPSS Score: %1.80
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024