Latest CVE Feed
-
10.0
CRITICALCVE-2024-25925
Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12. ... Read more
Affected Products : easy_checkout_field_editor- Published: Feb. 26, 2024
- Modified: May. 08, 2025
-
10.0
HIGHCVE-2017-8864
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as demonstrated by a client-side "if (!passwordsAreEqual())" t... Read more
- EPSS Score: %0.65
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2022-33206
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An att... Read more
Affected Products : iota_all-in-one_security_kit_firmware- EPSS Score: %0.45
- Published: Oct. 25, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-22055
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perform arbitrary operations on the sys... Read more
Affected Products : le-yan_dental_management_system- EPSS Score: %3.16
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-2974
The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, ... Read more
Affected Products : smc8024l2_switch- EPSS Score: %0.80
- Published: Jul. 19, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-49257
Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through 0.9.... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
10.0
CRITICALCVE-2024-49329
Unrestricted Upload of File with Dangerous Type vulnerability in Vivek Tamrakar WP REST API FNS allows Upload a Web Shell to a Web Server.This issue affects WP REST API FNS: from n/a through 1.0.0.... Read more
Affected Products : wp_rest_api_fns- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
10.0
CRITICALCVE-2024-49330
Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds allows Upload a Web Shell to a Web Server.This issue affects Nice Backgrounds: from n/a through 1.0.... Read more
Affected Products : nice_backgrounds- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
10.0
HIGHCVE-2019-7269
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.... Read more
Affected Products : linear_emerge_50p_firmware linear_emerge_5000p_firmware linear_emerge_50p linear_emerge_5000p- EPSS Score: %20.77
- Published: Jul. 02, 2019
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-23616
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. ... Read more
Affected Products : symantec_server_management_suite- EPSS Score: %6.30
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2022-22486
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM ... Read more
Affected Products : tivoli_workload_scheduler- EPSS Score: %0.02
- Published: Feb. 03, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-25096
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. ... Read more
Affected Products : canto- Published: Apr. 03, 2024
- Modified: Apr. 10, 2025
-
10.0
CRITICALCVE-2024-25100
Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2. ... Read more
Affected Products : coupon_referral_program- EPSS Score: %0.68
- Published: Feb. 12, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1043
Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.... Read more
- EPSS Score: %39.92
- Published: Mar. 23, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2012-3260
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.... Read more
Affected Products : sitescope- EPSS Score: %68.58
- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2021-26728
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500... Read more
- EPSS Score: %0.64
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-2912
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting t... Read more
Affected Products :- Published: Apr. 16, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-6926
Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.... Read more
Affected Products : extremail- EPSS Score: %0.38
- Published: Jan. 13, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2022-23166
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Sol... Read more
Affected Products : sysaid- EPSS Score: %0.44
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-6120
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation serv... Read more
- EPSS Score: %4.19
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024