Latest CVE Feed
-
9.3
CRITICALCVE-2025-40714
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo id_factura in /<Client>FacturaE/listado_facturas_ficha.jsp.... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-40715
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo mensaje in /QISClient/api/v1/sucesospaginas.... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2012-4607
Buffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code via crafted SunRPC data.... Read more
Affected Products : networker- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-1646
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.... Read more
Affected Products : mini-stream_rm_downloader- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-24664
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology LTL Freight Quotes – Worldwide Express Edition allows SQL Injection. This issue affects LTL Freight Quotes – Worldwide Express Edition... Read more
Affected Products : ltl_freight_quotes- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
9.3
HIGHCVE-2017-10831
Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : commercial_registration_electronic_authentication_software- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2018-4854
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legitimate user downloads and executes t... Read more
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-45367
The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
9.3
CRITICALCVE-2022-27660
A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.... Read more
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-1000006
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arb... Read more
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-5158
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvInfo004.dll file i... Read more
Affected Products : grundpaket_basis- Published: Sep. 07, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-0449
In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitat... Read more
Affected Products : android- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-48974
The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a co... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
9.3
HIGHCVE-2012-0224
Untrusted search path vulnerability in 7-Technologies (7T) AQUIS 1.5 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2012-0223.... Read more
Affected Products : aquis- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0113
Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2017-8142
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9869
drivers/media/platform/msm/camera_v2/isp/msm_isp_stats_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain index values, which allows attackers to gain privileges via a crafted applicati... Read more
Affected Products : android- Published: Aug. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2022-31512
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : flask-mvc- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-0134
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector... Read more
Affected Products : easy_grid_control- Published: Jan. 16, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2024-24986
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024