Latest CVE Feed
-
9.6
CRITICALCVE-2020-13292
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.... Read more
Affected Products : gitlab- Published: Aug. 10, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-47797
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.... Read more
Affected Products : liferay_portal- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-52138
Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Ar... Read more
Affected Products : engrampa- Published: Feb. 05, 2024
- Modified: Feb. 13, 2025
-
9.6
CRITICALCVE-2024-33006
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. ... Read more
Affected Products : netweaver_application_server_abap- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-7024
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)... Read more
Affected Products : chrome- Published: Sep. 23, 2024
- Modified: Jan. 02, 2025
-
9.6
CRITICALCVE-2024-20252
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected ... Read more
- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-1309
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-19947
Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.... Read more
Affected Products : markdown_edit- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.6
CRITICALCVE-2020-19825
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.... Read more
Affected Products : kimai- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
9.6
CRITICALCVE-2020-16018
Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-16017
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- Actively Exploited
- Published: Jan. 08, 2021
- Modified: Feb. 05, 2025
-
9.6
CRITICALCVE-2020-15999
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
Affected Products : fedora debian_linux ontap_select_deploy_administration_utility chrome backports_sle freetype- Actively Exploited
- Published: Nov. 03, 2020
- Modified: Feb. 05, 2025
-
9.6
CRITICALCVE-2020-15961
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more
- Published: Sep. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-16025
Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-14589
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this v... Read more
Affected Products : bamboo- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2018-0057
On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address bindi... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6465
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-15140
In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, i... Read more
Affected Products : red_discord_bot- Published: Aug. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-15121
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will crea... Read more
- Published: Jul. 20, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-12641
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, una... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024