Latest CVE Feed
-
9.8
CRITICALCVE-2023-25214
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more
- EPSS Score: %0.11
- Published: Apr. 07, 2023
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2023-25218
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more
- EPSS Score: %0.11
- Published: Apr. 07, 2023
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2023-25212
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more
- EPSS Score: %0.11
- Published: Apr. 07, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-25178
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning. ... Read more
- EPSS Score: %0.89
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25143
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.... Read more
- EPSS Score: %2.34
- Published: Mar. 10, 2023
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-25156
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround... Read more
Affected Products : kiwi_tcms- EPSS Score: %0.22
- Published: Feb. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6703
Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header... Read more
Affected Products : agent- EPSS Score: %2.82
- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6376
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.... Read more
Affected Products : joomla\!- EPSS Score: %7.38
- Published: Jan. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5924
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.... Read more
Affected Products : t8x44_firmware 3aw51a_firmware a9u28b_firmware d3a82a_firmware v1n08a_firmware y5h80a_firmware d4h24b_firmware f5s57a_firmware k4t99b_firmware k4u04b_firmware +530 more products- EPSS Score: %34.86
- Published: Aug. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25131
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Busine... Read more
Affected Products : powerpanel- EPSS Score: %0.34
- Published: Apr. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25366
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.... Read more
- EPSS Score: %0.22
- Published: Jun. 16, 2023
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2023-25181
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger thi... Read more
- EPSS Score: %0.22
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5488
NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00.0001 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the netw... Read more
- EPSS Score: %2.24
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-4991
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a security bypass.... Read more
Affected Products : creative_cloud- EPSS Score: %2.27
- Published: May. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-24813
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0... Read more
- Actively Exploited
- Published: Mar. 10, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2023-28843
PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote... Read more
Affected Products : paypal- EPSS Score: %0.22
- Published: Mar. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2004-0285
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.... Read more
- EPSS Score: %29.93
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-25078
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. ... Read more
- EPSS Score: %0.06
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-4148
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. A buffer overflow allows remote attackers to execute arbitrary code.... Read more
Affected Products : iphone_os- EPSS Score: %8.82
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-4147
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.... Read more
- EPSS Score: %0.78
- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024