Latest CVE Feed
-
9.8
CRITICALCVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows a... Read more
- Actively Exploited
- EPSS Score: %94.47
- Published: Jun. 04, 2019
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2018-13043
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.... Read more
- EPSS Score: %1.28
- Published: Jul. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12829
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation.... Read more
Affected Products : creative_cloud- EPSS Score: %2.10
- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12804
Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking.... Read more
Affected Products : connect- EPSS Score: %6.52
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12533
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData obje... Read more
Affected Products : richfaces- EPSS Score: %73.98
- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12474
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE... Read more
- EPSS Score: %0.38
- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11407
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, whi... Read more
Affected Products : symfony- EPSS Score: %0.20
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11325
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator accoun... Read more
Affected Products : joomla\!- EPSS Score: %0.11
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10992
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --... Read more
Affected Products : lilypond- EPSS Score: %0.77
- Published: May. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10191
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use th... Read more
- EPSS Score: %1.36
- Published: Apr. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-46476
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.... Read more
- EPSS Score: %62.91
- Published: Jan. 19, 2023
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-3657
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulati... Read more
Affected Products : ac_repair_and_services_system- EPSS Score: %0.05
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0608
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.... Read more
Affected Products : h2o- EPSS Score: %2.57
- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0399
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.... Read more
Affected Products : finesse- EPSS Score: %0.72
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47780
SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter.... Read more
Affected Products : bangresto- EPSS Score: %0.24
- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2018-0315
A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, re... Read more
- EPSS Score: %15.10
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0312
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulner... Read more
- EPSS Score: %2.84
- Published: Jun. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47854
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.... Read more
- EPSS Score: %0.09
- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-1099
A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipulation of the argument editid leads ... Read more
- EPSS Score: %0.05
- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0044
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords ... Read more
- EPSS Score: %0.42
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024