Latest CVE Feed
-
9.4
CRITICALCVE-2024-4999
A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MI... Read more
Affected Products :- Published: May. 16, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-5176
Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.... Read more
Affected Products :- Published: May. 31, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-3033
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including r... Read more
Affected Products : anythingllm- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-5128
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or dataset_prompt_variati... Read more
Affected Products : lunary- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-35307
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.... Read more
- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-32814
Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This securit... Read more
Affected Products : skytable- EPSS Score: %0.74
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-38492
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.... Read more
Affected Products : symantec_privileged_access_management- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-7093
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in thei... Read more
Affected Products : dispatch- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.4
HIGHCVE-2021-28506
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.... Read more
Affected Products : eos- EPSS Score: %0.28
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-0660
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.... Read more
- EPSS Score: %7.50
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-9137
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration fil... Read more
- Published: Oct. 14, 2024
- Modified: Jan. 17, 2025
-
9.4
CRITICALCVE-2023-32188
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.... Read more
Affected Products : neuvector- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
9.4
HIGHCVE-2021-35117
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +194 more products- EPSS Score: %0.24
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-46890
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privilege... Read more
Affected Products : sinec_ins- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.4
HIGHCVE-2021-46424
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.... Read more
- EPSS Score: %91.47
- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-52052
Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.... Read more
Affected Products : streaming_engine- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-35083
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon I... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +337 more products- EPSS Score: %0.16
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-10576
Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissi... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
9.4
CRITICALCVE-2022-2102
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in ... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- EPSS Score: %0.20
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-2105
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- EPSS Score: %0.19
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024