Latest CVE Feed
-
10.0
HIGHCVE-2012-2974
The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, ... Read more
Affected Products : smc8024l2_switch- EPSS Score: %0.80
- Published: Jul. 19, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-49257
Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through 0.9.... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
10.0
CRITICALCVE-2024-49329
Unrestricted Upload of File with Dangerous Type vulnerability in Vivek Tamrakar WP REST API FNS allows Upload a Web Shell to a Web Server.This issue affects WP REST API FNS: from n/a through 1.0.0.... Read more
Affected Products : wp_rest_api_fns- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
10.0
CRITICALCVE-2024-49330
Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds allows Upload a Web Shell to a Web Server.This issue affects Nice Backgrounds: from n/a through 1.0.... Read more
Affected Products : nice_backgrounds- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
10.0
HIGHCVE-2019-7269
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.... Read more
Affected Products : linear_emerge_50p_firmware linear_emerge_5000p_firmware linear_emerge_50p linear_emerge_5000p- EPSS Score: %20.77
- Published: Jul. 02, 2019
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-23616
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. ... Read more
Affected Products : symantec_server_management_suite- EPSS Score: %6.30
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2022-22486
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM ... Read more
Affected Products : tivoli_workload_scheduler- EPSS Score: %0.02
- Published: Feb. 03, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-25096
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. ... Read more
Affected Products : canto- Published: Apr. 03, 2024
- Modified: Apr. 10, 2025
-
10.0
CRITICALCVE-2024-25100
Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2. ... Read more
Affected Products : coupon_referral_program- EPSS Score: %0.68
- Published: Feb. 12, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1043
Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.... Read more
- EPSS Score: %39.92
- Published: Mar. 23, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2012-3260
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.... Read more
Affected Products : sitescope- EPSS Score: %68.58
- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2021-26728
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500... Read more
- EPSS Score: %0.64
- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-2912
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting t... Read more
Affected Products :- Published: Apr. 16, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-6926
Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.... Read more
Affected Products : extremail- EPSS Score: %0.38
- Published: Jan. 13, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2022-23166
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Sol... Read more
Affected Products : sysaid- EPSS Score: %0.44
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-6120
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation serv... Read more
- EPSS Score: %4.19
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-8940
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the ser... Read more
Affected Products : scriptcase- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
10.0
CRITICALCVE-2023-6018
An attacker can overwrite any file on the server hosting MLflow without any authentication.... Read more
Affected Products : mlflow- EPSS Score: %88.39
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-9479
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd server, as demonst... Read more
- EPSS Score: %2.34
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2024-7332
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded pass... Read more
- Published: Aug. 01, 2024
- Modified: Aug. 09, 2024