Latest CVE Feed
-
9.4
HIGHCVE-2019-5078
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can c... Read more
- EPSS Score: %0.67
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-9906
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.... Read more
- EPSS Score: %0.68
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2021-38162
SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes allow an unauthenticated attacker to submit a malicious crafted request over ... Read more
Affected Products : web_dispatcher- EPSS Score: %0.83
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-4210
IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.20
- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2025-34159
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose direc... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34157
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded J... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-34161
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the G... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-30063
The configuration file containing database logins and passwords is readable by any local user.... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
9.4
CRITICALCVE-2025-30057
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-30056
The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system.... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-2313
In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-47062
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furt... Read more
Affected Products : navidrome- Published: Sep. 20, 2024
- Modified: Aug. 26, 2025
-
9.4
CRITICALCVE-2025-34055
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the st... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34056
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are direc... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34074
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with access to /lucee/admin/web.cfm can configure a scheduled job to retrieve a re... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-48952
NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification using SHA-256 magic hashes, due to loose comparison in PHP. In vulnerable vers... Read more
Affected Products : netalertx- Published: Jul. 04, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-6793
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information on affected installat... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2024-13955
2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-46816
goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The function `dispatchReadPump` does not checks the option cli... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-26605
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_cargo.php` endpoint. This vulnerability could allow an authorized attacker to e... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Injection