Latest CVE Feed
-
9.3
HIGHCVE-2018-0858
ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, C... Read more
Affected Products : chakracore- EPSS Score: %30.16
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-5796
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.... Read more
Affected Products : j9627a_firmware j9626a_firmware j9625a_firmware j9624a_firmware j9623a_firmware j9627a j9626a j9625a j9624a j9623a- EPSS Score: %0.49
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2012-0771
Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759.... Read more
Affected Products : shockwave_player- EPSS Score: %6.37
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-15860
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management frame, a stack buffer overflow may potentially occur.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0543
Untrusted search path vulnerability in Jtrim 1.53c and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : jtrim- EPSS Score: %0.17
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-44393
Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited ... Read more
Affected Products : piwigo- EPSS Score: %4.70
- Published: Oct. 09, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8933
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.... Read more
- EPSS Score: %0.49
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8934
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.... Read more
- EPSS Score: %0.60
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-15325
The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Prague-AL00BC00B211, versions earlier than Prague-AL00CC00B211, versions earlier than Prague-TL00AC01B211, versions earlier than Prague-T... Read more
- EPSS Score: %0.11
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9141
On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105.... Read more
Affected Products : samsung_mobile- EPSS Score: %0.76
- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-17770
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in a power driver ioctl handler, an Untrusted Pointer Dereference may potentially occur.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-13277
In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: ... Read more
Affected Products : android- EPSS Score: %0.72
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-13252
In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input validation that results in a read from uninitialized memory. This could lead to local escalation of privilege with no additional execution privileges needed. Use... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10231
An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-12652
A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.... Read more
Affected Products :- Published: Dec. 26, 2024
- Modified: Dec. 26, 2024
-
9.3
CRITICALCVE-2021-27080
Azure Sphere Unsigned Code Execution Vulnerability... Read more
Affected Products : azure_sphere- EPSS Score: %0.32
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22709
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution w... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.70
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22711
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.13
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-54292
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsplate Appsplate allows SQL Injection.This issue affects Appsplate: from n/a through 2.1.3.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.3
HIGHCVE-2021-27245
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(US)_V5_200220 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists ... Read more
- EPSS Score: %4.21
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024