Latest CVE Feed
-
10.0
HIGHCVE-2011-1563
Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via (1) a long username in an On_FC_CONNECT_FCS_LOGIN packet, and crafted (2) On_FC_C... Read more
Affected Products : realwin- EPSS Score: %58.36
- Published: Apr. 05, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2021-38393
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agi... Read more
Affected Products : diaenergie- EPSS Score: %1.65
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-35003
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists withi... Read more
- EPSS Score: %10.63
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-11196
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Sna... Read more
Affected Products : sa6150p_firmware sa6155p_firmware sa8150p_firmware sa8155p_firmware sa8195p_firmware sdx55m_firmware qcm4290_firmware qcs4290_firmware sa6155_firmware sa8155_firmware +174 more products- EPSS Score: %0.36
- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-13997
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script... Read more
- EPSS Score: %1.59
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-13995
An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious attacker to access sensitive information such as HMI pa... Read more
Affected Products : ininet_webserver- EPSS Score: %1.60
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14002
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain ac... Read more
- EPSS Score: %15.38
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-27113
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.... Read more
- EPSS Score: %28.61
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-31474
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds... Read more
Affected Products : network_performance_monitor- EPSS Score: %53.63
- Published: May. 21, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-17269
Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.... Read more
Affected Products : remote_access- EPSS Score: %1.50
- Published: Oct. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3654
u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M... Read more
Affected Products : qca6390_firmware qca6574au_firmware sa6155p_firmware sa8155p_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware +72 more products- EPSS Score: %0.36
- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3657
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,... Read more
Affected Products : qca6574au_firmware ipq6018_firmware ipq8064_firmware ipq8074_firmware qrb5165_firmware sdx55_firmware sdm660_firmware sm8250_firmware msm8996au_firmware apq8096au_firmware +64 more products- EPSS Score: %3.07
- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2020-9411
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible... Read more
- EPSS Score: %0.38
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-25074
TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.... Read more
- EPSS Score: %3.35
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44622
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request.... Read more
- EPSS Score: %0.90
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2022-21643
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct... Read more
Affected Products : useful_simple_open-source_cms- EPSS Score: %0.26
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12072
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can complet... Read more
- EPSS Score: %0.36
- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-32449
TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.... Read more
- EPSS Score: %18.71
- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-4223
Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors.... Read more
Affected Products : sysinternals_debugview- EPSS Score: %9.41
- Published: Nov. 08, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-25913
Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. ... Read more
Affected Products : moveto- Published: Feb. 26, 2024
- Modified: May. 08, 2025