Latest CVE Feed
-
10.0
HIGHCVE-2018-5435
The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Des... Read more
- EPSS Score: %1.48
- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-1475
Unspecified vulnerability in the YagattaTalk Messenger (com.iskoot.yagatta.yagattatalk) application 1.00.01.08 for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.29
- Published: Mar. 14, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1476
Unspecified vulnerability in the KKtalk (com.kkliaotian.android) application 4.0.0 and 4.1.5 for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.33
- Published: Mar. 14, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1478
Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack vectors.... Read more
- EPSS Score: %0.33
- Published: Mar. 14, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2022-47893
There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.... Read more
- EPSS Score: %1.72
- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-28577
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.... Read more
- EPSS Score: %20.86
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2025-27140
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary co... Read more
Affected Products : wegia- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2018-5560
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device.... Read more
- EPSS Score: %0.47
- Published: Jan. 31, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-28896
A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.... Read more
- EPSS Score: %33.42
- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-2316
Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to have an unknown impact by calling the script "in txt mode from a browser."... Read more
Affected Products : open_business_management- EPSS Score: %0.85
- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-51545
Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
10.0
HIGHCVE-2014-8579
TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for remote attackers to obtain access via an FTP session.... Read more
- EPSS Score: %1.23
- Published: Jan. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-13925
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to... Read more
Affected Products : kylin- EPSS Score: %84.70
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-6503
Unspecified vulnerability in the NinjaXplorer component before 1.0.7 for Joomla! has unknown impact and attack vectors.... Read more
- EPSS Score: %0.42
- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-22004
Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application ... Read more
- Published: Apr. 05, 2024
- Modified: Jul. 24, 2025
-
10.0
HIGHCVE-2007-2494
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile,... Read more
Affected Products : powerpoint_viewer_ocx- EPSS Score: %10.23
- Published: May. 04, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2012-0231
PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TCP ses... Read more
Affected Products : intelligent_platforms_proficy_plant_applications- EPSS Score: %1.40
- Published: Mar. 15, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-0242
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.... Read more
Affected Products : advantech_webaccess- EPSS Score: %14.09
- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2021-31758
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.... Read more
- EPSS Score: %40.11
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-31891
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control ... Read more
Affected Products : debian_linux desigo_cc siveillance_control_pro gma-manager operation_scheduler siveillance_control- EPSS Score: %4.58
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024