Latest CVE Feed
-
9.6
CRITICALCVE-2024-21640
Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. This v... Read more
Affected Products : chromium_embedded_framework- EPSS Score: %0.25
- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-24799
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a... Read more
Affected Products : wire-webapp- EPSS Score: %0.56
- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-39160
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.... Read more
Affected Products : nbgitpuller- EPSS Score: %0.43
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-51219
A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP r... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Feb. 19, 2025
-
9.6
CRITICALCVE-2020-14705
Vulnerability in the Oracle GoldenGate product of Oracle GoldenGate (component: Process Management). The supported version that is affected is Prior to 19.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physica... Read more
Affected Products : goldengate- EPSS Score: %0.46
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-31229
Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploit this vulnerability, leading to disclosure of sensitive information. This sensitive information can be used to acc... Read more
Affected Products : powerscale_onefs- EPSS Score: %0.29
- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-48974
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.... Read more
Affected Products : axigen_mail_server- EPSS Score: %6.58
- Published: Feb. 08, 2024
- Modified: Jun. 17, 2025
-
9.6
CRITICALCVE-2023-27335
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this ... Read more
- Published: May. 03, 2024
- Modified: Aug. 13, 2025
-
9.6
CRITICALCVE-2016-6637
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x befor... Read more
- EPSS Score: %0.12
- Published: Sep. 30, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2018-9035
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.... Read more
Affected Products : contact-form-7-to-database-extension- EPSS Score: %8.82
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-3708
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of ... Read more
Affected Products : emc_isilonsd_management_server- EPSS Score: %0.56
- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26926
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbk752 rbr750 rbs750 +4 more products- EPSS Score: %0.15
- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-42496
Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject a... Read more
- Published: Feb. 21, 2024
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2017-2865
An exploitable vulnerability exists in the firmware update functionality of Circle with Disney. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An attacker can intercept and alter network traffic to trigge... Read more
- EPSS Score: %0.13
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2021-22943
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed in UniFi Protec... Read more
Affected Products : unifi_protect- EPSS Score: %0.12
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21382
Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration... Read more
Affected Products : restund- EPSS Score: %0.33
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-29078
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RB... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk753_firmware rbk753s_firmware rbk853_firmware rbk752 +12 more products- EPSS Score: %0.24
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-11059
In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the browser bundle published to npm. This has been fixed in 21.10.1.... Read more
Affected Products : aegir- EPSS Score: %0.37
- Published: May. 27, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-18563
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before ... Read more
- EPSS Score: %0.25
- Published: Nov. 20, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-45629
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and ... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr750_firmware rbk752 rbr750 rbs750 +4 more products- EPSS Score: %0.56
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024