Latest CVE Feed
-
9.8
CRITICALCVE-2018-10544
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.... Read more
- EPSS Score: %0.74
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2001-0395
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.... Read more
- EPSS Score: %1.13
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-1083
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.... Read more
Affected Products :- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10510
A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.... Read more
- EPSS Score: %3.80
- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10466
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.... Read more
Affected Products : manageengine_adaudit_plus- EPSS Score: %10.31
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10429
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.... Read more
Affected Products : cosmo- EPSS Score: %0.51
- Published: Apr. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10388
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.... Read more
Affected Products : open_tftp_server- EPSS Score: %18.15
- Published: Dec. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10389
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.... Read more
Affected Products : open_tftp_server- EPSS Score: %2.74
- Published: Dec. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10387
Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161.... Read more
Affected Products : open_tftp_server- EPSS Score: %8.19
- Published: Dec. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability... Read more
- EPSS Score: %91.15
- Published: Feb. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10362
An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, it is possible to login with a simpler password if the password has the fo... Read more
Affected Products : phpliteadmin- EPSS Score: %0.32
- Published: Apr. 25, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-21689
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_10_22h2 windows_server_2022 +6 more products- EPSS Score: %29.67
- Published: Feb. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10305
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.... Read more
Affected Products : simple_machines_forum- EPSS Score: %0.42
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10285
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.... Read more
Affected Products : ipecs_nms- EPSS Score: %48.83
- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10283
CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.... Read more
Affected Products : loja_virtual- EPSS Score: %0.26
- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10244
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.... Read more
- EPSS Score: %0.67
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3838
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protoco... Read more
Affected Products : dompdf- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2023-21708
Remote Procedure Call Runtime Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_10_22h2 windows_server_2022 +7 more products- EPSS Score: %4.72
- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10191
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use th... Read more
- EPSS Score: %1.36
- Published: Apr. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40520
Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.... Read more
- EPSS Score: %0.40
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024