Latest CVE Feed
-
9.6
CRITICALCVE-2020-13562
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL te... Read more
- EPSS Score: %19.36
- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-13563
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL tem... Read more
- EPSS Score: %19.96
- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-14442
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, R... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk753_firmware +14 more products- EPSS Score: %1.54
- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-47222
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in th... Read more
Affected Products : media_streaming_add-on- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21248
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by using dynamically generated Groovy cl... Read more
Affected Products : onedev- EPSS Score: %0.43
- Published: Jan. 15, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-32770
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user... Read more
Affected Products : avideo- EPSS Score: %15.19
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-25067
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.... Read more
- EPSS Score: %1.54
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-3638
Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricki... Read more
Affected Products : web_gateway- EPSS Score: %1.01
- Published: Sep. 12, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-48292
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an att... Read more
- EPSS Score: %0.26
- Published: Nov. 20, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0173
radare2 is vulnerable to Out-of-bounds Read... Read more
- EPSS Score: %0.37
- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-35391
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report... Read more
- EPSS Score: %16.96
- Published: Jan. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-9835
The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. This occurs because it accepts unencrypted 2.4 GHz packets, even though all legitimate communication uses AES encryption.... Read more
- EPSS Score: %0.06
- Published: Mar. 15, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-2881
An exploitable vulnerability exists in the torlist update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An attacker can intercept and alter net... Read more
- EPSS Score: %0.25
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2020-14441
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, R... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk753_firmware +14 more products- EPSS Score: %1.54
- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-45520
Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.... Read more
- EPSS Score: %0.23
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-29065
NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.... Read more
- EPSS Score: %0.10
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-23510
cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.3... Read more
Affected Products : cube.js- EPSS Score: %0.03
- Published: Dec. 09, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-25395
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.... Read more
Affected Products : cosmetics_and_beauty_product_online_store- EPSS Score: %0.37
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-25772
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript... Read more
Affected Products : mautic- EPSS Score: %2.07
- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-24229
The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to ... Read more
Affected Products : patreon_wordpress- EPSS Score: %0.64
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024