Latest CVE Feed
-
9.4
CRITICALCVE-2019-17638
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ... Read more
Affected Products : jetty- EPSS Score: %27.65
- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2017-10917
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.... Read more
Affected Products : xen- EPSS Score: %0.84
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.4
HIGHCVE-2016-2208
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.... Read more
Affected Products : anti-virus_engine- EPSS Score: %52.67
- Published: May. 19, 2016
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2016-3541
Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Notes.... Read more
- EPSS Score: %1.36
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-12106
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.... Read more
Affected Products : whatsup_gold- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
9.4
CRITICALCVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other... Read more
- EPSS Score: %0.37
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2008-5407
Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and r... Read more
Affected Products : backup_exec_for_windows_server- EPSS Score: %1.39
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2016-1034
The Sync Process in the JavaScript API for Creative Cloud Libraries in Adobe Creative Cloud Desktop Application before 3.6.0.244 allows remote attackers to read or write to arbitrary files via unspecified vectors.... Read more
Affected Products : creative_cloud- EPSS Score: %1.44
- Published: Apr. 12, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2023-49581
SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. B... Read more
Affected Products : netweaver_application_server_abap- EPSS Score: %0.07
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2007-6480
The Oracle database component in Sun Management Center (Sun MC) 3.6.1, 3.6, and 3.5 Update 1 has a default account, which allows remote attackers to obtain database access and execute arbitrary code.... Read more
- EPSS Score: %5.27
- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2019-15926
An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.... Read more
- EPSS Score: %3.91
- Published: Sep. 04, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-1297
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files ... Read more
Affected Products : rv160_vpn_router_firmware rv160w_wireless-ac_vpn_router_firmware rv260_vpn_router_firmware rv260p_vpn_router_with_poe_firmware small_business_rv_series_router_firmware rv260w_wireless-ac_vpn_router_firmware rv160w_wireless-ac_vpn_router rv260_vpn_router rv260p_vpn_router_with_poe rv260w_wireless-ac_vpn_router +1 more products- EPSS Score: %0.44
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-5078
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can c... Read more
- EPSS Score: %0.67
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-9906
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.... Read more
- EPSS Score: %0.68
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2021-38162
SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes allow an unauthenticated attacker to submit a malicious crafted request over ... Read more
Affected Products : web_dispatcher- EPSS Score: %0.83
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-4210
IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.20
- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2025-34159
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose direc... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34157
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded J... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-34161
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the G... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-30063
The configuration file containing database logins and passwords is readable by any local user.... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure