Latest CVE Feed
-
9.8
CRITICALCVE-2023-28503
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to... Read more
- EPSS Score: %65.09
- Published: Mar. 29, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2014-9410
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate a certain... Read more
Affected Products : linux_kernel- EPSS Score: %0.25
- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2023-6901
A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an unknown part of the file /terminal/handle-command.php of the component HTTP POST Request Handler. The manipulation of the argument comm... Read more
Affected Products : stupid_simple_cms- EPSS Score: %0.64
- Published: Dec. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19078
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password.... Read more
Affected Products : c2 i5_application_firmware i5_system_firmware c2_application_firmware c2_system_firmware i5- EPSS Score: %0.58
- Published: Nov. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-9814
A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an unknown function of the file product/update.php. The manipulation of the argument id leads to sql injection. It is possible to launch t... Read more
Affected Products : pharmacy_management_system- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
9.8
CRITICALCVE-2018-1999022
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, H... Read more
- EPSS Score: %1.40
- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18957
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.... Read more
Affected Products : libiec61850- EPSS Score: %5.35
- Published: Nov. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18949
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.... Read more
Affected Products : manageengine_opmanager- EPSS Score: %12.83
- Published: Nov. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18934
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be execute... Read more
Affected Products : popojicms- EPSS Score: %0.13
- Published: Nov. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18923
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and st... Read more
Affected Products : ticketly- EPSS Score: %5.47
- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18922
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.... Read more
Affected Products : ticketly- EPSS Score: %4.34
- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18887
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).... Read more
Affected Products : s-cms- EPSS Score: %0.26
- Published: Nov. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18912
An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execut... Read more
Affected Products : easy_file_sharing_web_server- EPSS Score: %2.87
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18861
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.... Read more
Affected Products : pcman_ftp_server- EPSS Score: %2.58
- Published: Nov. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18814
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker t... Read more
- EPSS Score: %2.07
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4657
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.... Read more
Affected Products : ansible- EPSS Score: %2.24
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18888
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.... Read more
Affected Products : laravelcms- EPSS Score: %0.43
- Published: Nov. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18834
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.... Read more
Affected Products : libiec61850- EPSS Score: %0.46
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18801
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].... Read more
Affected Products : bsen_ordering_software- EPSS Score: %3.03
- Published: Nov. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18795
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.... Read more
Affected Products : school_event_management_system- EPSS Score: %3.03
- Published: Nov. 16, 2018
- Modified: Nov. 21, 2024