Latest CVE Feed
-
9.6
CRITICALCVE-2023-29050
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and pote... Read more
- EPSS Score: %0.11
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-24593
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation o... Read more
Affected Products : clearml- EPSS Score: %0.42
- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-46332
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 ... Read more
Affected Products : enterprise_protection- EPSS Score: %0.43
- Published: Dec. 06, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-25147
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attack... Read more
- Published: Feb. 21, 2024
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2024-26269
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote atta... Read more
- Published: Feb. 21, 2024
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2024-0440
Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.... Read more
Affected Products : anythingllm- Published: Feb. 26, 2024
- Modified: Feb. 27, 2025
-
9.6
CRITICALCVE-2024-0550
A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissio... Read more
Affected Products : anythingllm- Published: Feb. 28, 2024
- Modified: Jan. 10, 2025
-
9.6
CRITICALCVE-2020-35124
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.... Read more
Affected Products : mautic- EPSS Score: %1.14
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32692
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visit... Read more
- EPSS Score: %0.06
- Published: Dec. 23, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-2792
An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can p... Read more
Affected Products : marklogic- EPSS Score: %0.65
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-3679
Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.... Read more
Affected Products : data_center_manager- EPSS Score: %0.38
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2015-10073
A vulnerability, which was classified as problematic, was found in tinymighty WikiSEO 1.2.1 on MediaWiki. This affects the function modifyHTML of the file WikiSEO.body.php of the component Meta Property Tag Handler. The manipulation of the argument conten... Read more
Affected Products : wikiseo- EPSS Score: %0.13
- Published: Feb. 06, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-14443
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole ... Read more
- EPSS Score: %0.62
- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32853
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from maliciou... Read more
Affected Products : erxes- EPSS Score: %85.50
- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-3329
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack... Read more
Affected Products : zephyr- EPSS Score: %0.05
- Published: Feb. 26, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-19947
Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.... Read more
Affected Products : markdown_edit- EPSS Score: %0.37
- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.6
CRITICALCVE-2023-28131
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicio... Read more
Affected Products : expo_software_development_kit- EPSS Score: %0.95
- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025
-
9.6
CRITICALCVE-2023-31126
`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes... Read more
Affected Products : xwiki- EPSS Score: %3.27
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.... Read more
Affected Products : ip_office- EPSS Score: %28.59
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2023-21516
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.... Read more
Affected Products : galaxy_store- EPSS Score: %0.36
- Published: May. 26, 2023
- Modified: Nov. 21, 2024