Latest CVE Feed
-
9.3
CRITICALCVE-2025-46271
UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.... Read more
Affected Products :- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-40619
Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-4041
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-47657
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds Productive Commerce allows SQL Injection. This issue affects Productive Commerce: from n/a through 1.1.22.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-22199
This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentia... Read more
Affected Products : django- EPSS Score: %1.78
- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-0815
Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0... Read more
- Published: Mar. 07, 2024
- Modified: Jan. 19, 2025
-
9.3
CRITICALCVE-2024-33559
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5. ... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-5021
The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to m... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-6160
SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session cookies or modify the content of pages. This issue affects MegaBIP software versions through 5.12.1.... Read more
Affected Products : megabip- Published: Jun. 24, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-6198
Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.... Read more
Affected Products :- Published: Jun. 25, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-37260
Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.... Read more
Affected Products : foxiz- Published: Jul. 06, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-21876
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envo... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 23, 2024
-
9.3
CRITICALCVE-2024-23981
Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
9.3
CRITICALCVE-2024-24759
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to d... Read more
Affected Products : mindsdb- Published: Sep. 05, 2024
- Modified: Sep. 06, 2024
-
9.3
HIGHCVE-2017-0664
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36491278.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0665
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36991414.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0667
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37478824.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0671
A remote code execution vulnerability in the Android libraries. Product: Android. Versions: 4.4.4. Android ID: A-34514762.... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0673
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33974623.... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0676
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34896431.... Read more
Affected Products : android- EPSS Score: %0.29
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025