Latest CVE Feed
-
9.4
HIGHCVE-2020-0371
There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008256... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-0376
There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163003156... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-13871
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, ... Read more
- Published: Mar. 12, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-3476
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2021-27312
Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.... Read more
Affected Products : gleez_cms- Published: Apr. 03, 2024
- Modified: Apr. 16, 2025
-
9.4
CRITICALCVE-2024-25511
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.... Read more
Affected Products : ruvaroa- Published: May. 07, 2024
- Modified: Apr. 16, 2025
-
9.4
CRITICALCVE-2024-34947
Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.... Read more
Affected Products :- Published: May. 20, 2024
- Modified: Mar. 25, 2025
-
9.4
CRITICALCVE-2024-0336
Improper Access Control vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDKS: before 20240603. NOTE: The vendor was contacted early about this disclosure but did not respond in a... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-36059
Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.... Read more
Affected Products :- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-7205
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.... Read more
Affected Products : ewelink- Published: Jul. 31, 2024
- Modified: Jul. 31, 2024
-
9.4
CRITICALCVE-2024-41940
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privilege... Read more
Affected Products : sinec_nms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
9.4
CRITICALCVE-2024-36439
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.... Read more
Affected Products :- Published: Aug. 22, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-42764
Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.... Read more
Affected Products : bus_ticket_reservation_system- Published: Aug. 23, 2024
- Modified: May. 06, 2025
-
9.4
CRITICALCVE-2024-7873
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order... Read more
Affected Products :- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
9.4
CRITICALCVE-2022-0942
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.... Read more
Affected Products : showdoc- EPSS Score: %0.33
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1330
stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .... Read more
Affected Products : fullpage- EPSS Score: %0.32
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1592
Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...... Read more
Affected Products : scout- EPSS Score: %0.30
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1682
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser... Read more
Affected Products : facturascripts- EPSS Score: %0.28
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2021-27442
The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.... Read more
Affected Products : cmt-svr-100_firmware cmt-svr-102_firmware cmt-svr-200_firmware cmt-svr-202_firmware cmt-g01_firmware cmt-g02_firmware cmt-g03_firmware cmt-g04_firmware cmt3071_firmware cmt3072_firmware +22 more products- EPSS Score: %0.14
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2016-5843
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.... Read more
Affected Products : faq- EPSS Score: %1.10
- Published: Sep. 17, 2016
- Modified: Apr. 12, 2025