Latest CVE Feed
-
9.3
HIGHCVE-2016-10692
haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker contr... Read more
Affected Products : haxeshim- EPSS Score: %1.64
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10694
alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code executio... Read more
Affected Products : alto-saxophone- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10695
The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swa... Read more
Affected Products : npm-test-sqlite3-trunk- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-5850
In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kerne... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jun. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-33030
Memory corruption in HLOS while running playready use-case.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +586 more products- EPSS Score: %0.06
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-23786
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is access... Read more
- EPSS Score: %2.54
- Published: Feb. 14, 2024
- Modified: Mar. 18, 2025
-
9.3
CRITICALCVE-2024-25625
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability involves a Host Header Injection in the `invitationLink... Read more
Affected Products : admin_classic_bundle- Published: Feb. 19, 2024
- Modified: Apr. 01, 2025
-
9.3
HIGHCVE-2021-26914
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.... Read more
Affected Products : netmotion_mobility- EPSS Score: %64.44
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-46823
A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V... Read more
Affected Products : saml- EPSS Score: %0.46
- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2856
An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully... Read more
- EPSS Score: %0.42
- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-17208
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the... Read more
- EPSS Score: %16.69
- Published: Sep. 19, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-13140
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.... Read more
- EPSS Score: %5.06
- Published: Sep. 24, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9077
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary co... Read more
Affected Products : lenovoemc_firmware iomega_ez_media_\&_backup_center iomega_storcenter_ix2 iomega_storcenter_ix2-dl iomega_storcenter_ix4-300d iomega_storcenter_px12-400r iomega_storcenter_px12-450r iomega_storcenter_px2-300d iomega_storcenter_px4-300d iomega_storcenter_px4-300r +12 more products- EPSS Score: %1.87
- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-42833
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.... Read more
Affected Products : aquaview- EPSS Score: %0.04
- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9491
In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in external apps with no additional execution privileges needed. User interaction is needed for... Read more
Affected Products : android- EPSS Score: %0.33
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9497
In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed ... Read more
Affected Products : android- EPSS Score: %0.41
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-0796
A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0800
A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-14262
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.... Read more
Affected Products : srn_1670d_firmware srn_1000_firmware srn_472s_firmware srn_470d_firmware srn_1670d srn_1000 srn_472s srn_470d- EPSS Score: %21.02
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10855
Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- EPSS Score: %0.14
- Published: Sep. 15, 2017
- Modified: Apr. 20, 2025