Latest CVE Feed
-
9.5
CRITICALCVE-2024-52330
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.... Read more
Affected Products :- Published: Jan. 23, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Misconfiguration
-
9.4
CRITICALCVE-2013-10067
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-34147
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-56320
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authe... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2025-54079
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the endpoint `/html/atendido/Profile_Atendido.php`, in the `idatendido` par... Read more
Affected Products : wegia- Published: Jul. 18, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54058
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_... Read more
Affected Products : wegia- Published: Jul. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
HIGHCVE-2007-2170
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE i... Read more
Affected Products : e-business_suite- EPSS Score: %1.89
- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-2439
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.... Read more
- EPSS Score: %1.56
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-3192
admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.... Read more
Affected Products : just_for_fun_network_management_system- EPSS Score: %2.86
- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2014-2634
Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.... Read more
Affected Products : service_manager- EPSS Score: %6.59
- Published: Aug. 23, 2014
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-8384
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecifi... Read more
- EPSS Score: %1.06
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGH- EPSS Score: %68.25
- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-13625
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.... Read more
Affected Products : ghidra- EPSS Score: %0.32
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-16383
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Micr... Read more
Affected Products : moveit_transfer- EPSS Score: %1.28
- Published: Sep. 24, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-14082
Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Inf... Read more
Affected Products : ipq8074_firmware sm8150_firmware qcn7605_firmware mdm9206_firmware mdm9607_firmware mdm9207c_firmware mdm9206 mdm9607 ipq8074 qcn7605 +2 more products- EPSS Score: %0.24
- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-3652
Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check of length of variable received. in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850... Read more
Affected Products : qca6390_firmware msm8998_firmware sc7180_firmware sc8180x_firmware sdm850_firmware qca6390 msm8998 sc7180 sc8180x sdm850- EPSS Score: %0.24
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-20695
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects SRK60 before 2.3.5.106, SRR60 before 2.3.5.106, and SRS60 before 2.3.5.106.... Read more
- EPSS Score: %0.57
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2020-10286
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot opera... Read more
- EPSS Score: %0.20
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-0283
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008257... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-0339
There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-162980705... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024