Latest CVE Feed
-
9.6
CRITICALCVE-2018-0264
A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability ... Read more
Affected Products : webex_meeting_server webex_meetings webex_business_suite_32 webex_business_suite_31- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-4947
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 15, 2024
- Modified: Nov. 27, 2024
-
9.6
CRITICALCVE-2024-4558
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: May. 07, 2024
- Modified: Dec. 20, 2024
-
9.6
CRITICALCVE-2024-38824
Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.... Read more
Affected Products : salt- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Path Traversal
-
9.6
CRITICALCVE-2024-12108
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.... Read more
- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
9.6
CRITICALCVE-2023-2136
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: Apr. 19, 2023
- Modified: Feb. 19, 2025
-
9.6
CRITICALCVE-2024-49362
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a... Read more
Affected Products : joplin- Published: Nov. 14, 2024
- Modified: May. 07, 2025
-
9.6
CRITICALCVE-2021-38002
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21132
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-2446
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc... Read more
Affected Products : secure_global_desktop- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-3510
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with network... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2019-10784
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker... Read more
Affected Products : phppgadmin- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-3289
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacke... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-3272
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticate... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2021-29996
Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.... Read more
Affected Products : marktext- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-5053
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexO... Read more
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-2881
An exploitable vulnerability exists in the torlist update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An attacker can intercept and alter net... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2024-44778
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.... Read more
Affected Products : vtiger_crm- Published: Aug. 29, 2024
- Modified: Sep. 03, 2024
-
9.6
CRITICALCVE-2017-2792
An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can p... Read more
Affected Products : marklogic- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-10086
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols... Read more
Affected Products : debian_linux active_iq_unified_manager cloud_backup oncommand_balance oncommand_insight oncommand_performance_manager oncommand_unified_manager jdk jre e-series_santricity_os_controller +9 more products- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025