Latest CVE Feed
-
9.3
CRITICALCVE-2018-4006
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere on the system. A user with local access can use this vulnerability to raise... Read more
Affected Products : shimo_vpn- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10433
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415,... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware msm8909w_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware sd_410_firmware sd_412_firmware +38 more products- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10562
iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested ... Read more
Affected Products : iedriver- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-34083
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved fr... Read more
Affected Products : google-it- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-24532
HEVC Video Extensions Remote Code Execution Vulnerability... Read more
Affected Products : hevc_video_extensions- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-4471
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via ... Read more
- Published: Oct. 07, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-17896
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify infor... Read more
Affected Products : fcj_firmware fcn-100_firmware fcn-rtu_firmware fcn-500_firmware fcj fcn-100 fcn-rtu fcn-500- Published: Oct. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-37566
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7610, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bound... Read more
Affected Products : mt7613_firmware mt7615_firmware mt7622_firmware mt7628_firmware mt7629_firmware mt7915_firmware mt7603e_firmware mt7620_firmware mt7610_firmware mt7603e +8 more products- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-4071
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.... Read more
- Published: May. 09, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-41274
solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any versio... Read more
Affected Products : solidus_auth_devise- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2020-13537
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService... Read more
Affected Products : mxview- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-33072
Memory corruption in Core while processing control functions.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +484 more products- Published: Feb. 06, 2024
- Modified: Aug. 11, 2025
-
9.3
HIGHCVE-2008-5002
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could b... Read more
Affected Products : chilkat_crypt_activex_control- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2020-4721
IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute a... Read more
Affected Products : i2_analysts_notebook- Published: Oct. 29, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-5232
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attacker... Read more
- Published: Nov. 26, 2008
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2020-15123
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE ... Read more
Affected Products : codecov- Published: Jul. 20, 2020
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-6013
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.... Read more
Affected Products : h2o- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-16087
An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.... Read more
- Published: Aug. 13, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-16215
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modificati... Read more
Affected Products : webaccess\/hmi_designer- Published: Aug. 06, 2020
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-6569
External Control of File Name or Path in h2oai/h2o-3... Read more
- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024