Latest CVE Feed
-
9.6
CRITICALCVE-2023-27335
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this ... Read more
- Published: May. 03, 2024
- Modified: Aug. 13, 2025
-
9.6
CRITICALCVE-2016-6637
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x befor... Read more
- Published: Sep. 30, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2018-9035
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.... Read more
Affected Products : contact-form-7-to-database-extension- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-3708
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of ... Read more
Affected Products : emc_isilonsd_management_server- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26926
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbk752 rbr750 rbs750 +4 more products- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-42496
Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject a... Read more
- Published: Feb. 21, 2024
- Modified: Jan. 28, 2025
-
9.6
CRITICALCVE-2017-2865
An exploitable vulnerability exists in the firmware update functionality of Circle with Disney. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An attacker can intercept and alter network traffic to trigge... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2021-22943
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed in UniFi Protec... Read more
Affected Products : unifi_protect- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21382
Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration... Read more
Affected Products : restund- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-29078
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RB... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk753_firmware rbk753s_firmware rbk853_firmware rbk752 +12 more products- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-11059
In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the browser bundle published to npm. This has been fixed in 21.10.1.... Read more
Affected Products : aegir- Published: May. 27, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-18563
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before ... Read more
- Published: Nov. 20, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-45629
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and ... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr750_firmware rbk752 rbr750 rbs750 +4 more products- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-14440
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, R... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk753_firmware +14 more products- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-0957
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, becaus... Read more
Affected Products : gitpod- Published: Mar. 03, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-24508
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed wi... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-1347
Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation... Read more
Affected Products : organizr- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-5241
The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file... Read more
- Published: Oct. 19, 2023
- Modified: May. 12, 2025
-
9.6
CRITICALCVE-2024-25292
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter.... Read more
Affected Products : rendertune- Published: Feb. 29, 2024
- Modified: Mar. 27, 2025
-
9.6
CRITICALCVE-2024-27132
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables. ... Read more
Affected Products : mlflow- Published: Feb. 23, 2024
- Modified: Jan. 22, 2025