Latest CVE Feed
-
9.8
CRITICALCVE-2017-6195
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6165
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Netw... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +2 more products- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-23369
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versio... Read more
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23364
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability i... Read more
Affected Products : multimedia_console- Published: Sep. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6131
In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instanc... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-23333
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.... Read more
- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-23303
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method wit... Read more
Affected Products : connect-iq- Published: May. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5792
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.... Read more
Affected Products : intelligent_management_center- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23300
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafte... Read more
Affected Products : connect-iq- Published: May. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23298
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the ... Read more
Affected Products : connect-iq- Published: May. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23279
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.... Read more
Affected Products : canteen_management_system- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-23155
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.... Read more
Affected Products : art_gallery_management_system- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23162
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.... Read more
Affected Products : art_gallery_management_system- Published: Feb. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23150
SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.... Read more
- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2023-23149
DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.... Read more
- Published: Mar. 24, 2023
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2017-4923
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.... Read more
Affected Products : vcenter_server- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-23156
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.... Read more
Affected Products : art_gallery_management_system- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23076
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.... Read more
Affected Products : manageengine_supportcenter_plus- Published: Feb. 01, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2003-0899
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences... Read more
Affected Products : thttpd- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2025-1010
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption