Latest CVE Feed
-
9.3
CRITICALCVE-2025-52551
E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in the file system.... Read more
Affected Products :- Published: Sep. 02, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2024-4332
An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, a... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Aug. 29, 2025
-
9.3
HIGHCVE-2020-17127
Microsoft Excel Remote Code Execution Vulnerability... Read more
Affected Products : excel- EPSS Score: %6.28
- Published: Dec. 10, 2020
- Modified: Aug. 28, 2025
-
9.3
CRITICALCVE-2024-13979
A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-34162
An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails ... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2010-2568
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly h... Read more
Affected Products : windows_7 windows_server_2008 windows_2003_server windows_server_2003 windows_vista windows_xp- Actively Exploited
- EPSS Score: %93.20
- Published: Jul. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
CRITICALCVE-2024-1485
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archiv... Read more
- EPSS Score: %0.81
- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2011-10032
Sunway ForceControl version 6.1 SP3 and earlier contains a stack-based buffer overflow vulnerability in the SNMP NetDBServer service, which listens on TCP port 2001. The flaw is triggered when the service receives a specially crafted packet using opcode 0... Read more
Affected Products :- Published: Aug. 30, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Memory Corruption
-
9.3
CRITICALCVE-2022-31557
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : golem- EPSS Score: %0.44
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2025-6519
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.... Read more
Affected Products :- Published: Sep. 02, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2009-20010
Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability arises from unsanitized user input passed via a POST request to the data parameter, which is processed by th... Read more
Affected Products :- Published: Aug. 30, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-54943
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.... Read more
Affected Products :- Published: Aug. 30, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-52856
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioSto... Read more
Affected Products :- Published: Aug. 29, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
9.3
HIGHCVE-2020-17128
Microsoft Excel Remote Code Execution Vulnerability... Read more
Affected Products : office 365_apps office_web_apps excel office_online_server office_2016 excel_2016 office_2019 office_web_apps_2013 excel_2013- EPSS Score: %6.14
- Published: Dec. 10, 2020
- Modified: Aug. 28, 2025
-
9.3
HIGHCVE-2020-17125
Microsoft Excel Remote Code Execution Vulnerability... Read more
Affected Products : office 365_apps office_web_apps excel office_online_server excel_2016 office_2019 office_web_apps_2013 excel_2013- EPSS Score: %6.28
- Published: Dec. 10, 2020
- Modified: Aug. 28, 2025
-
9.3
HIGHCVE-2020-17123
Microsoft Excel Remote Code Execution Vulnerability... Read more
Affected Products : office 365_apps office_web_apps excel office_online_server excel_2016 office_2021 office_2019 office_web_apps_2013 excel_2013- EPSS Score: %5.24
- Published: Dec. 10, 2020
- Modified: Aug. 28, 2025
-
9.3
CRITICALCVE-2025-39496
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injection.This issue affects WooBeWoo Product Filter Pro: from n/a before 2.9.6.... Read more
Affected Products :- Published: Aug. 28, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-2697
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to s... Read more
Affected Products : cognos_command_center- Published: Aug. 26, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Misconfiguration
-
9.3
HIGHCVE-2008-0888
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free ... Read more
- EPSS Score: %21.44
- Published: Mar. 17, 2008
- Modified: May. 01, 2025
-
9.3
CRITICALCVE-2025-9074
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Iso... Read more
Affected Products : desktop- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization