Latest CVE Feed
-
9.6
CRITICALCVE-2017-2336
A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including th... Read more
Affected Products : screenos- EPSS Score: %0.24
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2016-5582
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.... Read more
- EPSS Score: %7.19
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2020-9758
An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege es... Read more
Affected Products : livezilla- EPSS Score: %2.40
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-28763
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary ne... Read more
- EPSS Score: %0.45
- Published: Oct. 31, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-9002
An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Administrator access).... Read more
Affected Products : iportalis_control_portal- EPSS Score: %0.31
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-8976
The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and tri... Read more
- EPSS Score: %0.25
- Published: Oct. 17, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-8105
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_... Read more
- EPSS Score: %0.40
- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-7361
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'p... Read more
Affected Products : zentao_pro- EPSS Score: %35.97
- Published: Aug. 06, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6573
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %2.07
- Published: Sep. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6522
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %2.07
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6509
Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
Affected Products : chrome- EPSS Score: %0.26
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6493
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %3.61
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6471
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
- EPSS Score: %0.86
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6466
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %1.49
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6469
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
- EPSS Score: %0.70
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-5948
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP s... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +1 more products- EPSS Score: %0.82
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-34716
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the c... Read more
Affected Products : prestashop- Published: May. 14, 2024
- Modified: Jan. 21, 2025
-
9.6
CRITICALCVE-2024-34359
llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to conf... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6457
Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %1.07
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2015-10073
A vulnerability, which was classified as problematic, was found in tinymighty WikiSEO 1.2.1 on MediaWiki. This affects the function modifyHTML of the file WikiSEO.body.php of the component Meta Property Tag Handler. The manipulation of the argument conten... Read more
Affected Products : wikiseo- EPSS Score: %0.14
- Published: Feb. 06, 2023
- Modified: Nov. 21, 2024