Latest CVE Feed
-
9.6
CRITICALCVE-2024-44778
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.... Read more
Affected Products : vtiger_crm- Published: Aug. 29, 2024
- Modified: Sep. 03, 2024
-
9.6
CRITICALCVE-2017-2792
An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can p... Read more
Affected Products : marklogic- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-10086
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols... Read more
Affected Products : debian_linux active_iq_unified_manager cloud_backup oncommand_balance oncommand_insight oncommand_performance_manager oncommand_unified_manager jdk jre e-series_santricity_os_controller +9 more products- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2016-3606
Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2013-3486
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability... Read more
Affected Products : flashpix_plugin- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-23278
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with action removeBackground and server/node_upgrade_srv.js with action r... Read more
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21799
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted... Read more
Affected Products : r-seenet- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21803
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more
Affected Products : r-seenet- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-8980
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA t... Read more
- Published: Oct. 22, 2024
- Modified: Dec. 10, 2024
-
9.6
CRITICALCVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 28, 2024
- Modified: Nov. 27, 2024
-
9.6
CRITICALCVE-2024-23466
SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. ... Read more
Affected Products : access_rights_manager- Published: Jul. 17, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-14443
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole ... Read more
- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-43984
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.... Read more
Affected Products : podlove_podcast_publisher- Published: Oct. 31, 2024
- Modified: Mar. 19, 2025
-
9.6
CRITICALCVE-2017-12367
A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wi... Read more
Affected Products : webex_meetings_server- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-12369
A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a... Read more
Affected Products : webex_meetings- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-12370
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a use... Read more
Affected Products : webex_meetings- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2022-0290
Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Feb. 12, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.... Read more
Affected Products : ip_office- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2021-22201
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.... Read more
Affected Products : gitlab- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-10107
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated atta... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025