Latest CVE Feed
-
10.0
CRITICALCVE-2024-25139
In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that ... Read more
Affected Products : omada_er605_firmware- Published: Mar. 14, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-40629
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the Ansible pl... Read more
Affected Products : jumpserver- Published: Jul. 18, 2024
- Modified: Mar. 25, 2025
-
10.0
HIGHCVE-2007-0863
PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: h... Read more
Affected Products : trevorchan- EPSS Score: %4.34
- Published: Feb. 09, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2021-29908
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.... Read more
- EPSS Score: %0.61
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-39967
WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identif... Read more
- EPSS Score: %0.60
- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-9117
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attacker... Read more
- EPSS Score: %9.27
- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-10487
Buffer over read can happen while parsing SMS OTA messages at transport layer if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voi... Read more
Affected Products : sdx55_firmware sdm660_firmware sm8150_firmware msm8996au_firmware apq8096au_firmware mdm9150_firmware qcs605_firmware sdx24_firmware apq8009_firmware mdm9650_firmware +96 more products- EPSS Score: %0.40
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-9161
WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to ... Read more
- EPSS Score: %3.68
- Published: Apr. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-2543
Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), ... Read more
- EPSS Score: %0.47
- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-1014
Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.... Read more
Affected Products : vicftps- EPSS Score: %21.54
- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-4165
Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1263.... Read more
Affected Products : database_archiving_software- EPSS Score: %31.27
- Published: Dec. 29, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0360
Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, relate... Read more
Affected Products : java_system_web_server- EPSS Score: %0.80
- Published: Jan. 20, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2019-10511
Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ80... Read more
Affected Products : sdx55_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware mdm9150_firmware qcs605_firmware sdx24_firmware +100 more products- EPSS Score: %0.31
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-2753
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow rem... Read more
Affected Products : informix_dynamic_server- EPSS Score: %23.22
- Published: Mar. 05, 2010
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2023-37470
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase ... Read more
Affected Products : metabase- EPSS Score: %3.35
- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-8669
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : customer_relationship_management- EPSS Score: %9.97
- Published: Nov. 06, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2012-1382
Unspecified vulnerability in the Youdao Dictionary (com.youdao.dict) application 1.6.1, 2.0.1(2), and 3.0.0(1) for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.33
- Published: Mar. 07, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1384
Unspecified vulnerability in the NetEase Pmail (com.netease.rpmms) application 0.5.0 and 0.5.2 for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.43
- Published: Mar. 07, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-1000042
Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This at... Read more
Affected Products : squert- EPSS Score: %2.19
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-1402
Unspecified vulnerability in the QianXun YingShi (com.qianxun.yingshi) application 1.2.3 and 1.3.4 for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.43
- Published: Mar. 07, 2012
- Modified: Apr. 11, 2025