Latest CVE Feed
-
9.4
CRITICALCVE-2024-39815
Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of serv... Read more
Affected Products : var1200-h_firmware var1200-h var1200-l_firmware var1200-l var600-h_firmware var600-h vap11ac_firmware vap11ac vap11g-500s_firmware vap11g-500s +18 more products- Published: Aug. 12, 2024
- Modified: Aug. 20, 2024
-
9.4
HIGHCVE-2016-0699
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.... Read more
- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-37802
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.... Read more
Affected Products : health_care_hospital_management_system- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-36439
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.... Read more
Affected Products :- Published: Aug. 22, 2024
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-9906
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.... Read more
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-8470
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not re... Read more
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2015-6259
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via cra... Read more
- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-35783
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2... Read more
- Published: Sep. 10, 2024
- Modified: Jan. 14, 2025
-
9.4
HIGHCVE-2017-10917
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.... Read more
Affected Products : xen- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.4
HIGHCVE-2016-2208
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.... Read more
Affected Products : anti-virus_engine- Published: May. 19, 2016
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2016-3541
Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Notes.... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-33499
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1... Read more
Affected Products : simatic_rtls_locating_manager- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-32838
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query paramet... Read more
Affected Products : fineract- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-12106
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.... Read more
Affected Products : whatsup_gold- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
9.4
HIGHCVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character ... Read more
Affected Products : netsweeper- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-8567
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.... Read more
- Published: Nov. 14, 2014
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other... Read more
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2008-5407
Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and r... Read more
Affected Products : backup_exec_for_windows_server- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2020-3634
u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ... Read more
Affected Products : sdx55_firmware sdm660_firmware sm8150_firmware msm8996au_firmware apq8096au_firmware mdm9150_firmware qcs610_firmware sa415m_firmware qcs605_firmware sdx24_firmware +90 more products- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2014-6221
The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 does not properly generate random numbers, which makes it easier for remote attackers to defeat crypt... Read more
Affected Products : rational_clearcase- Published: Apr. 06, 2015
- Modified: Apr. 12, 2025