Latest CVE Feed
-
9.3
HIGHCVE-2016-10677
google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-latest downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to caus... Read more
Affected Products : google-closure-tools-latest- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10678
serc.js is a Selenium RC process wrapper serc.js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled ... Read more
Affected Products : serc.js- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10683
arcanist downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or posit... Read more
Affected Products : arcanist- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10687
windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swap... Read more
Affected Products : windows-selenium-chromedriver- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10692
haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker contr... Read more
Affected Products : haxeshim- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10694
alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code executio... Read more
Affected Products : alto-saxophone- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10695
The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swa... Read more
Affected Products : npm-test-sqlite3-trunk- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-5850
In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kerne... Read more
Affected Products : android- Published: Jun. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-33030
Memory corruption in HLOS while running playready use-case.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +586 more products- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-23786
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is access... Read more
- Published: Feb. 14, 2024
- Modified: Mar. 18, 2025
-
9.3
CRITICALCVE-2024-25625
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability involves a Host Header Injection in the `invitationLink... Read more
Affected Products : admin_classic_bundle- Published: Feb. 19, 2024
- Modified: Apr. 01, 2025
-
9.3
HIGHCVE-2021-26914
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.... Read more
Affected Products : netmotion_mobility- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-46823
A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V... Read more
Affected Products : saml- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2856
An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully... Read more
- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-17208
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the... Read more
- Published: Sep. 19, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-13140
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.... Read more
- Published: Sep. 24, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9077
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary co... Read more
Affected Products : lenovoemc_firmware iomega_ez_media_\&_backup_center iomega_storcenter_ix2 iomega_storcenter_ix2-dl iomega_storcenter_ix4-300d iomega_storcenter_px12-400r iomega_storcenter_px12-450r iomega_storcenter_px2-300d iomega_storcenter_px4-300d iomega_storcenter_px4-300r +12 more products- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-42833
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.... Read more
Affected Products : aquaview- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9491
In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in external apps with no additional execution privileges needed. User interaction is needed for... Read more
Affected Products : android- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9497
In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed ... Read more
Affected Products : android- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024