Latest CVE Feed
-
9.4
HIGHCVE-2013-3658
Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors.... Read more
- Published: Sep. 10, 2013
- Modified: Apr. 11, 2025
-
9.4
HIGHCVE-2021-1296
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files ... Read more
Affected Products : rv160_vpn_router_firmware rv160w_wireless-ac_vpn_router_firmware rv260_vpn_router_firmware rv260p_vpn_router_with_poe_firmware small_business_rv_series_router_firmware rv260w_wireless-ac_vpn_router_firmware rv160w_wireless-ac_vpn_router rv260_vpn_router rv260p_vpn_router_with_poe rv260w_wireless-ac_vpn_router +1 more products- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-39815
Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of serv... Read more
Affected Products : var1200-h_firmware var1200-h var1200-l_firmware var1200-l var600-h_firmware var600-h vap11ac_firmware vap11ac vap11g-500s_firmware vap11g-500s +18 more products- Published: Aug. 12, 2024
- Modified: Aug. 20, 2024
-
9.4
HIGHCVE-2016-0699
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.... Read more
- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-37802
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.... Read more
Affected Products : health_care_hospital_management_system- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-36439
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.... Read more
Affected Products :- Published: Aug. 22, 2024
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-9906
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.... Read more
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2020-8470
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not re... Read more
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2015-6259
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via cra... Read more
- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-35783
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2... Read more
- Published: Sep. 10, 2024
- Modified: Jan. 14, 2025
-
9.4
HIGHCVE-2017-10917
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.... Read more
Affected Products : xen- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.4
HIGHCVE-2016-2208
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.... Read more
Affected Products : anti-virus_engine- Published: May. 19, 2016
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2016-3541
Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Notes.... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2024-33499
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1... Read more
Affected Products : simatic_rtls_locating_manager- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-32838
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query paramet... Read more
Affected Products : fineract- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-12106
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.... Read more
Affected Products : whatsup_gold- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
9.4
HIGHCVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character ... Read more
Affected Products : netsweeper- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-8567
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.... Read more
- Published: Nov. 14, 2014
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other... Read more
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2008-5407
Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and r... Read more
Affected Products : backup_exec_for_windows_server- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025