Latest CVE Feed
-
9.6
CRITICALCVE-2024-34070
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malic... Read more
Affected Products : froxlor- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-20195
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. T... Read more
- EPSS Score: %0.30
- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-2361
A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
9.6
CRITICALCVE-2024-35592
An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code via uploading a crafted PDF file.... Read more
Affected Products :- Published: May. 24, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-3149
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headless b... Read more
Affected Products : anythingllm- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-26088
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.... Read more
- EPSS Score: %5.48
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-36411
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix fo... Read more
Affected Products : suitecrm- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21800
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted us... Read more
Affected Products : r-seenet- EPSS Score: %72.46
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-38373
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with dom... Read more
Affected Products : freertos-plus-tcp- Published: Jun. 24, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-54372
Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify allows Code Injection.This issue affects Insertify: from n/a through 1.1.4.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.6
CRITICALCVE-2024-23997
Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.... Read more
Affected Products : yana- Published: Jul. 05, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-23998
goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.... Read more
Affected Products : another_redis_desktop_manager- Published: Jul. 05, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-9002
An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Administrator access).... Read more
Affected Products : iportalis_control_portal- EPSS Score: %0.31
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-41603
Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.... Read more
Affected Products : spina- Published: Jul. 19, 2024
- Modified: May. 29, 2025
-
9.6
CRITICALCVE-2024-39777
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID ... Read more
- Published: Aug. 01, 2024
- Modified: Aug. 23, 2024
-
9.6
CRITICALCVE-2021-38480
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the... Read more
- EPSS Score: %0.09
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-23754
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.... Read more
Affected Products : phpfusion- EPSS Score: %0.81
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-20982
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.... Read more
Affected Products : wdja_cms- EPSS Score: %35.60
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-36779
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.... Read more
Affected Products : longhorn- EPSS Score: %0.05
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-8105
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_... Read more
- EPSS Score: %0.40
- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024