Latest CVE Feed
-
9.6
CRITICALCVE-2021-3994
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : django-helpdesk- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-3693
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.... Read more
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-3210
components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.... Read more
Affected Products : bloodhound- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 14, 2024
- Modified: Nov. 27, 2024
-
9.6
CRITICALCVE-2021-38013
Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Actively Exploited
- Published: Oct. 08, 2021
- Modified: Feb. 03, 2025
-
9.6
CRITICALCVE-2024-23469
SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. ... Read more
Affected Products : access_rights_manager- Published: Jul. 17, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-37208
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM... Read more
Affected Products : ruggedcom_ros ruggedcom_rsg2488 ruggedcom_rsl910 ruggedcom_i800 ruggedcom_i801 ruggedcom_i802 ruggedcom_i803 ruggedcom_m969 ruggedcom_m2100 ruggedcom_m2200 +44 more products- Published: Mar. 08, 2022
- Modified: Aug. 12, 2025
-
9.6
CRITICALCVE-2021-35222
This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page.... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-52308
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remot... Read more
Affected Products : cli- Published: Nov. 14, 2024
- Modified: Nov. 20, 2024
-
9.6
CRITICALCVE-2024-52053
Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.... Read more
Affected Products : streaming_engine- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-51962
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges. There is a high impact to integrity and... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection
-
9.6
CRITICALCVE-2021-33672
Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the ... Read more
Affected Products : contact_center- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0977
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 21, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0790
Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-0452
Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-33387
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.... Read more
Affected Products : minicms- Published: Feb. 24, 2023
- Modified: Mar. 12, 2025
-
9.6
CRITICAL- Published: Dec. 15, 2021
- Modified: Jun. 11, 2025
-
9.6
CRITICALCVE-2021-32827
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on th... Read more
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32630
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature.... Read more
Affected Products : admidio- Published: May. 20, 2021
- Modified: Nov. 21, 2024