Latest CVE Feed
-
9.6
CRITICALCVE-2024-22093
When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software vers... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +2 more products- EPSS Score: %0.38
- Published: Feb. 14, 2024
- Modified: Jan. 23, 2025
-
9.6
CRITICALCVE-2024-28231
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS pr... Read more
Affected Products : fast_dds- Published: Mar. 20, 2024
- Modified: Jun. 30, 2025
-
9.6
CRITICALCVE-2021-37981
Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %1.62
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-26384
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vul... Read more
- EPSS Score: %0.10
- Published: Dec. 22, 2022
- Modified: Apr. 16, 2025
-
9.6
CRITICALCVE-2020-13292
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.... Read more
Affected Products : gitlab- EPSS Score: %0.09
- Published: Aug. 10, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-47797
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.... Read more
Affected Products : liferay_portal- EPSS Score: %0.15
- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-52138
Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Ar... Read more
Affected Products : engrampa- EPSS Score: %1.88
- Published: Feb. 05, 2024
- Modified: Feb. 13, 2025
-
9.6
CRITICALCVE-2024-33006
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. ... Read more
Affected Products : netweaver_application_server_abap- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-7024
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)... Read more
Affected Products : chrome- Published: Sep. 23, 2024
- Modified: Jan. 02, 2025
-
9.6
CRITICALCVE-2024-20252
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected ... Read more
- EPSS Score: %7.07
- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-1309
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %0.54
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-19947
Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.... Read more
Affected Products : markdown_edit- EPSS Score: %0.37
- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.6
CRITICALCVE-2020-19825
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.... Read more
Affected Products : kimai- EPSS Score: %0.39
- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
9.6
CRITICALCVE-2020-16018
Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- EPSS Score: %0.32
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-16017
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- Actively Exploited
- EPSS Score: %17.65
- Published: Jan. 08, 2021
- Modified: Feb. 05, 2025
-
9.6
CRITICALCVE-2020-15999
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
Affected Products : fedora debian_linux ontap_select_deploy_administration_utility chrome backports_sle freetype- Actively Exploited
- EPSS Score: %93.15
- Published: Nov. 03, 2020
- Modified: Feb. 05, 2025
-
9.6
CRITICALCVE-2020-15961
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
- EPSS Score: %1.51
- Published: Sep. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-16025
Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- EPSS Score: %0.84
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-14589
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this v... Read more
Affected Products : bamboo- EPSS Score: %0.44
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2018-0057
On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address bindi... Read more
Affected Products : junos- EPSS Score: %0.34
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024