Latest CVE Feed
-
9.8
CRITICALCVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.... Read more
Affected Products : moodle- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2018-15616
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 t... Read more
Affected Products : avaya_aura_system_platform- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15531
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37723
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting.... Read more
Affected Products : f1202_firmware fh1202_firmware pw201a_firmware 4g300_firmware pa202_firmware f1202 fh1202 pw201a 4g300 pa202- Published: Jul. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15506
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesyste... Read more
Affected Products : bubbleupnp- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15534
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003.... Read more
- Published: Aug. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15540
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.... Read more
Affected Products : cockpit- Published: Oct. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15441
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries.... Read more
Affected Products : prime_license_manager- Published: Nov. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15494
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.... Read more
- Published: Aug. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15482
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.... Read more
- Published: Aug. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8684
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to com... Read more
- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-24025
Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0... Read more
Affected Products : hhvm- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15389
A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during instal... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15386
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to an insecure defau... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23432
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()... Read more
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-36632
A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype poll... Read more
Affected Products : flat- Published: Dec. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15361
UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.... Read more
Affected Products : ultravnc- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4119
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.... Read more
Affected Products : caml-light- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23321
There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.... Read more
Affected Products : jerryscript- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15143
Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.... Read more
Affected Products : openemr- Published: Aug. 13, 2018
- Modified: Nov. 21, 2024