Latest CVE Feed
-
9.3
CRITICALCVE-2024-25331
DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.... Read more
Affected Products :- Published: Mar. 12, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-55978
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation.com Code Generator Pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through 1.2.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.3
CRITICALCVE-2024-6060
An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.... Read more
Affected Products :- Published: Jun. 25, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-28787
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. ... Read more
- Published: Mar. 26, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-8074
Improper Privilege Management vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users.This issue affects Nomysem: before 13.10.2024.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-1605
Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: ... Read more
- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICAL- Published: Jan. 20, 2024
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-2970
Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execute arbitrary code via the filename parameter.... Read more
- Published: Oct. 19, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-26943
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes allows Blind SQL Injection. This issue affects Easy Quotes: from n/a through 1.2.2.... Read more
Affected Products :- Published: Feb. 25, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2023-37538
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). ... Read more
Affected Products : digital_experience- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0103
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the ... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2025-32778
Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). The issue stems from user-controlled input (url) being passed unsanitized into a ... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-41370
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-1143
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.... Read more
Affected Products : central_dogma- Published: Feb. 02, 2024
- Modified: Jun. 03, 2025
-
9.3
HIGHCVE-2009-1640
Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file.... Read more
Affected Products : kernel_recovery- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2261
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .zip archive with a .txt file whose name contains | (pipe) characters and a command.... Read more
Affected Products : peazip- Published: Jun. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-0649
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except pa... Read more
Affected Products : nod32_antivirus smart_security compusec deslock\+_pro internet_security smart_security_premium- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-4088
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a ... Read more
Affected Products : gx_works3 gx_works2 melsoft_iq_appportal melsoft_navigator ezsocket fr_configurator2 mx_component- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-7717
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.... Read more
Affected Products : android- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2020-0002
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android ... Read more
Affected Products : android- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024