Latest CVE Feed
-
10.0
CRITICALCVE-2025-32440
NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.p... Read more
Affected Products : netalertx- Published: May. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
10.0
HIGHCVE-2020-28951
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.... Read more
Affected Products : openwrt- EPSS Score: %0.52
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-32494
Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service. ... Read more
Affected Products : radare2- EPSS Score: %0.19
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-25438
Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.... Read more
- EPSS Score: %15.92
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-5407
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructur... Read more
- Published: May. 27, 2024
- Modified: Jun. 05, 2025
-
10.0
HIGHCVE-2012-0695
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.... Read more
- EPSS Score: %0.22
- Published: Jan. 12, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-7165
A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).... Read more
Affected Products : intelligent_management_center- EPSS Score: %2.83
- Published: Oct. 19, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-32671
Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta before v1.0.0) and was not noticed or do... Read more
Affected Products : flarum- EPSS Score: %3.24
- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-0318
The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.... Read more
- EPSS Score: %1.38
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2023-48426
u-boot bug that allows for u-boot shell and interrupt over UART ... Read more
- Published: Apr. 05, 2024
- Modified: Jul. 24, 2025
-
10.0
CRITICALCVE-2024-23615
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. ... Read more
Affected Products : symantec_messaging_gateway- EPSS Score: %6.30
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-0839
post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal ... Read more
Affected Products : android- EPSS Score: %1.22
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2024-23622
A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges. ... Read more
Affected Products : merge_efilm_workstation- EPSS Score: %0.95
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-0474
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr... Read more
Affected Products : android- EPSS Score: %3.88
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-3686
cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.... Read more
Affected Products : airlive_wl2600cam- EPSS Score: %34.79
- Published: Oct. 11, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2007-6092
Buffer overflow in libsrtp in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.... Read more
- EPSS Score: %0.39
- Published: Nov. 22, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-3667
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.... Read more
Affected Products : financial_fusion_consumer_banking_solution- EPSS Score: %0.48
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2007-1697
PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.... Read more
Affected Products : philex- EPSS Score: %35.19
- Published: Mar. 27, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-4936
Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.... Read more
Affected Products : moodle- EPSS Score: %0.38
- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2009-3341
Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure ... Read more
- EPSS Score: %5.28
- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025