Latest CVE Feed
-
9.5
CRITICALCVE-2025-1077
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server conf... Read more
Affected Products :- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2013-10067
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-34147
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-56320
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authe... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2025-34148
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54079
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the endpoint `/html/atendido/Profile_Atendido.php`, in the `idatendido` par... Read more
Affected Products : wegia- Published: Jul. 18, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54058
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_... Read more
Affected Products : wegia- Published: Jul. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-53825
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
9.4
HIGHCVE-2005-4332
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmw... Read more
Affected Products : network_admission_control_manager_and_server_system_software- EPSS Score: %11.06
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
9.4
HIGHCVE-2007-2170
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE i... Read more
Affected Products : e-business_suite- EPSS Score: %1.89
- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-2439
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.... Read more
- EPSS Score: %1.56
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-3192
admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.... Read more
Affected Products : just_for_fun_network_management_system- EPSS Score: %2.68
- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2014-2634
Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.... Read more
Affected Products : service_manager- EPSS Score: %6.59
- Published: Aug. 23, 2014
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-8384
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecifi... Read more
- EPSS Score: %1.06
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character ... Read more
Affected Products : netsweeper- EPSS Score: %8.69
- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGH- EPSS Score: %68.25
- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-13625
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.... Read more
Affected Products : ghidra- EPSS Score: %0.32
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2018-14062
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal.... Read more
Affected Products : cospas-sarsat_system- EPSS Score: %0.76
- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-16383
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Micr... Read more
Affected Products : moveit_transfer- EPSS Score: %1.28
- Published: Sep. 24, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-10579
Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,... Read more
Affected Products : qca6574au_firmware sa6155p_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware qcs605_firmware apq8009_firmware +84 more products- EPSS Score: %0.24
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024