Latest CVE Feed
-
9.6
CRITICALCVE-2025-6514
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL... Read more
Affected Products :- Published: Jul. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.6
CRITICALCVE-2021-21802
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more
Affected Products : r-seenet- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-28813
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the ... Read more
Affected Products : qsw-m2116p-2t2s_firmware qunetswitch qsw-m2116p-2t2s qgd-1600p qgd-1602p qgd-3014pt- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6492
Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-45500
Certain NETGEAR devices are affected by authentication bypass. This affects R7000P before 1.3.3.140 and R8000 before 1.0.4.68.... Read more
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2015-20105
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it cou... Read more
Affected Products : clickbank_affiliate_ads- Published: Dec. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-44458
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attac... Read more
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-3882
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote co... Read more
Affected Products : rv110w rv215w small_business_rv_router_firmware small_business_rv_router_firmware_1.0 rv132w rv134w rv042 rv042g rv320 rv325 +7 more products- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2021-44749
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation.... Read more
Affected Products : safe- Published: Mar. 06, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-46732
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping.... Read more
Affected Products : xwiki- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-46242
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in ord... Read more
Affected Products : xwiki- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICAL- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-29050
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and pote... Read more
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-25147
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attack... Read more
- Published: Feb. 21, 2024
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2024-26269
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote atta... Read more
- Published: Feb. 21, 2024
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2020-35124
A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.... Read more
Affected Products : mautic- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32692
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visit... Read more
- Published: Dec. 23, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32853
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from maliciou... Read more
Affected Products : erxes- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-3329
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack... Read more
Affected Products : zephyr- Published: Feb. 26, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-28131
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicio... Read more
Affected Products : expo_software_development_kit- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025