Latest CVE Feed
-
10.0
HIGHCVE-2025-2618
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The ... Read more
- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2024-49326
Unrestricted Upload of File with Dangerous Type vulnerability in Vasilis Kerasiotis Affiliator allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through 2.1.3.... Read more
Affected Products : affiliator- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
10.0
HIGHCVE-2012-1477
Unspecified vulnerability in the Cnectd (mci.cnectd) application 3.1.0 for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.33
- Published: Mar. 14, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-3818
Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.... Read more
- EPSS Score: %0.35
- Published: Oct. 28, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-0224
In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code execution when processing a proxy configuration with no additional execution privileges needed. User interaction i... Read more
Affected Products : android- EPSS Score: %0.64
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-1406
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.... Read more
- EPSS Score: %0.44
- Published: Mar. 10, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-50526
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.... Read more
Affected Products : multi_purpose_mail_form- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
HIGHCVE-2011-4524
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.... Read more
Affected Products : advantech_webaccess- EPSS Score: %2.39
- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2007-2352
Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tool... Read more
Affected Products : afflib- EPSS Score: %8.95
- Published: Apr. 30, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-51549
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
10.0
CRITICALCVE-2024-48839
Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
10.0
CRITICALCVE-2024-52490
Unrestricted Upload of File with Dangerous Type vulnerability in Pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through 2.5.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
10.0
CRITICALCVE-2023-40151
When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UD... Read more
Affected Products : st-ipm-6350_firmware st-ipm-8460_firmware vt-mipm-135-d_firmware vt-mipm-245-d_firmware vt-ipm2m-213-d_firmware vt-ipm2m-113-d_firmware st-ipm-6350 st-ipm-8460 vt-mipm-135-d vt-mipm-245-d +2 more products- EPSS Score: %0.25
- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2018-1000821
MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Spe... Read more
Affected Products : micromathematics- EPSS Score: %0.24
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-29392
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.... Read more
- EPSS Score: %0.46
- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-22039
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribu... Read more
Affected Products : cerberus_pro_en_engineering_tool cerberus_pro_en_fire_panel_fc72x cerberus_pro_en_x200_cloud_distribution cerberus_pro_en_x300_cloud_distribution sinteso_fs20_en_engineering_tool sinteso_fs20_en_fire_panel_fc20 sinteso_fs20_en_x200_cloud_distribution sinteso_fs20_en_x300_cloud_distribution sinteso_mobile- Published: Mar. 12, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-5227
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.... Read more
- EPSS Score: %78.00
- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-49668
Unrestricted Upload of File with Dangerous Type vulnerability in Admin Verbalize WP Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 23, 2024
- Modified: Oct. 25, 2024
-
10.0
HIGHCVE-2019-9930
Various Lexmark products have an Integer Overflow.... Read more
Affected Products : cx310_firmware mx31x_firmware xm3150_firmware mx71x_firmware mx81x_firmware xm51xx_firmware xm71xx_firmware mx91x_firmware xm91x_firmware x74x_firmware +132 more products- EPSS Score: %0.44
- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-0238
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : advantech_webaccess- EPSS Score: %2.39
- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025