Latest CVE Feed
-
9.4
CRITICALCVE-2014-125118
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid userna... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-30135
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-53695
OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.... Read more
Affected Products : istar_ultra_firmware- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54298
A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-54299
A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2024-32838
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query paramet... Read more
Affected Products : fineract- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-53120
A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server.... Read more
Affected Products :- Published: Aug. 25, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-25182
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with A... Read more
Affected Products : stroom- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
9.4
HIGHCVE-2008-1454
Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remot... Read more
- EPSS Score: %51.89
- Published: Jul. 08, 2008
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-2386
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.... Read more
- EPSS Score: %71.93
- Published: May. 24, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2014-8567
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.... Read more
- EPSS Score: %4.43
- Published: Nov. 14, 2014
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2023-22644
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.... Read more
Affected Products : manager_server- EPSS Score: %0.04
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2025-57761
WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html/funcionario/dependente_remover.php endpoint, specifically in the id_funcionario parameter. This vulnerability allows attackers to exec... Read more
Affected Products : wegia- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-24902
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access... Read more
Affected Products : wegia- Published: Feb. 03, 2025
- Modified: Aug. 22, 2025
-
9.4
CRITICALCVE-2025-27494
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an aut... Read more
- Published: Mar. 11, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2023-4966
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.... Read more
- Actively Exploited
- EPSS Score: %94.30
- Published: Oct. 10, 2023
- Modified: Mar. 13, 2025
-
9.4
HIGHCVE-2019-8527
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.... Read more
- EPSS Score: %0.97
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-17137
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not required to exploit this vulnerability. The specific flaw ex... Read more
- EPSS Score: %0.43
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2008-5518
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) ... Read more
- EPSS Score: %15.78
- Published: Apr. 17, 2009
- Modified: Apr. 09, 2025
-
9.4
CRITICALCVE-2025-3463
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow untrusted sources to affect system behavior via crafted HTTP requests. Refer t... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025