Latest CVE Feed
-
9.6
CRITICALCVE-2024-27133
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table ... Read more
Affected Products : mlflow- Published: Feb. 23, 2024
- Modified: Jan. 22, 2025
-
9.6
CRITICALCVE-2024-11986
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resul... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.6
CRITICALCVE-2024-0765
As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and read that export that would enable you do exfiltrate data of the system at that save state. This would req... Read more
Affected Products : anythingllm- Published: Mar. 03, 2024
- Modified: Jan. 08, 2025
-
9.6
CRITICALCVE-2020-15146
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public serv... Read more
- EPSS Score: %1.06
- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-36990
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write... Read more
- EPSS Score: %0.38
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-21487
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.... Read more
- EPSS Score: %0.53
- Published: Apr. 04, 2023
- Modified: Feb. 13, 2025
-
9.6
CRITICALCVE-2025-54982
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
9.6
CRITICALCVE-2025-52950
A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web interface. Numerous endpoints on the Juniper Security Director ap... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2022-28755
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary n... Read more
- EPSS Score: %0.48
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-21326
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability... Read more
Affected Products : edge_chromium- EPSS Score: %0.76
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21109
Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %1.31
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-13363
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates... Read more
Affected Products : piwigo- EPSS Score: %0.30
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6167
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.... Read more
Affected Products : minimal_coming_soon_\&_maintenance_mode- EPSS Score: %0.73
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-18853
Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and earlier, R6400v2 1.0.2.18 and earlier, R6700 1.0.1.22 and ... Read more
Affected Products : wndr4500_firmware dgn2200_firmware r6300_firmware r6700_firmware r6900_firmware r7000_firmware r7000p_firmware r6400_firmware r7900_firmware r8000_firmware +22 more products- EPSS Score: %0.41
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-8904
An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and writ... Read more
Affected Products : asylo- EPSS Score: %0.06
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2025-52571
Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is p... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication
-
9.6
CRITICALCVE-2023-31546
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.... Read more
Affected Products : dedebiz- EPSS Score: %21.20
- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-3966
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.... Read more
Affected Products : zephyr- EPSS Score: %0.06
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-35125
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).... Read more
Affected Products : mautic- EPSS Score: %1.25
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-45506
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr750_firmware rbk752 rbr750 rbs750 +4 more products- EPSS Score: %0.08
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024