Latest CVE Feed
-
9.8
CRITICALCVE-2018-16239
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.... Read more
Affected Products : damicms- EPSS Score: %0.44
- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-16203
PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgreSQL database via unspecified vectors.... Read more
Affected Products : pgpooladmin- EPSS Score: %0.92
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-5357
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.... Read more
Affected Products : ektron_content_management_system- EPSS Score: %82.60
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-16278
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.... Read more
Affected Products : phpopensourcecms- EPSS Score: %1.80
- Published: Aug. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2615
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.... Read more
Affected Products : firefox- Published: Mar. 19, 2024
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2024-1676
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Feb. 21, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2018-15888
An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp page, they can be registered with the super administrators GroupID directly.... Read more
- EPSS Score: %0.99
- Published: Aug. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15868
SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.... Read more
Affected Products : chronoscan- EPSS Score: %1.44
- Published: Jun. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-2781
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2780.... Read more
Affected Products : ffmpeg- EPSS Score: %0.41
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2012-2778
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2780, and CVE-2012-2781.... Read more
Affected Products : ffmpeg- EPSS Score: %0.41
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15720
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.... Read more
- EPSS Score: %0.82
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15616
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 t... Read more
Affected Products : avaya_aura_system_platform- EPSS Score: %4.36
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15531
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.... Read more
- EPSS Score: %18.99
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37723
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting.... Read more
Affected Products : f1202_firmware fh1202_firmware pw201a_firmware 4g300_firmware pa202_firmware f1202 fh1202 pw201a 4g300 pa202- EPSS Score: %0.12
- Published: Jul. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15506
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesyste... Read more
Affected Products : bubbleupnp- EPSS Score: %2.14
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15534
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003.... Read more
- EPSS Score: %19.34
- Published: Aug. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15540
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.... Read more
Affected Products : cockpit- EPSS Score: %0.44
- Published: Oct. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15441
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries.... Read more
Affected Products : prime_license_manager- EPSS Score: %0.42
- Published: Nov. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15494
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.... Read more
- EPSS Score: %0.64
- Published: Aug. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15482
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.... Read more
- EPSS Score: %0.09
- Published: Aug. 17, 2018
- Modified: Nov. 21, 2024