Latest CVE Feed
-
9.4
HIGHCVE-2021-35117
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +194 more products- EPSS Score: %0.24
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-46890
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privilege... Read more
Affected Products : sinec_ins- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.4
HIGHCVE-2021-46424
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.... Read more
- EPSS Score: %91.47
- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-52052
Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.... Read more
Affected Products : streaming_engine- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-35083
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon I... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +337 more products- EPSS Score: %0.16
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-10576
Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissi... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
9.4
CRITICALCVE-2022-2102
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in ... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- EPSS Score: %0.20
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-2105
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.... Read more
Affected Products : sepcos_control_and_protection_relay_firmware sepcos_control_and_protection_relay- EPSS Score: %0.19
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-22524
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .... Read more
- EPSS Score: %0.32
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2025-0324
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.... Read more
Affected Products : axis_os- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2024-13967
This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web Server of EIBPORT. This issue affects EIBPORT V3 KNX: through 3.9.8; EIBPORT V3 KNX GSM: through 3.9.8.... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-34071
A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgrade mechanism accepts unsigned .img files, which can be ... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-2523
The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, whic... Read more
Affected Products : c200e_firmware- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Memory Corruption
-
9.4
CRITICALCVE-2025-52579
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory befor... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cryptography
-
9.4
CRITICALCVE-2025-54062
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `/html/funcionario/profile_dependente.php` endpoint, specifically in th... Read more
Affected Products : wegia- Published: Jul. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34150
The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is processed unsafely during network setup, allowing attackers to execute arbitrary syste... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2012-10059
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitr... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2023-1834
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the devic... Read more
- EPSS Score: %0.24
- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-1897
Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.... Read more
- EPSS Score: %0.04
- Published: Jun. 12, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-33987
An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERN... Read more
Affected Products : web_dispatcher- EPSS Score: %0.14
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024