Latest CVE Feed
-
10.0
HIGHCVE-2021-44622
A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request.... Read more
- EPSS Score: %0.90
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2022-21643
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct... Read more
Affected Products : useful_simple_open-source_cms- EPSS Score: %0.26
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12072
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can complet... Read more
- EPSS Score: %0.36
- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-32449
TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.... Read more
- EPSS Score: %18.71
- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-4223
Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors.... Read more
Affected Products : sysinternals_debugview- EPSS Score: %9.41
- Published: Nov. 08, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-25913
Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. ... Read more
Affected Products : moveto- Published: Feb. 26, 2024
- Modified: May. 08, 2025
-
10.0
HIGHCVE-2015-1801
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corruption) or gain privileges.... Read more
- EPSS Score: %0.91
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2012-3270
Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-... Read more
Affected Products : performance_insight- EPSS Score: %3.31
- Published: Nov. 07, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2017-14475
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with t... Read more
Affected Products : mysql_multi-master_replication_manager- EPSS Score: %4.97
- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-2578
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerN... Read more
- EPSS Score: %72.28
- Published: Oct. 11, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2007-3232
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet dae... Read more
Affected Products : totalstorage_ds400- EPSS Score: %1.35
- Published: Jun. 15, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2015-2052
Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a GetDeviceSettings action to the HNAP interface.... Read more
- EPSS Score: %11.65
- Published: Feb. 23, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2020-12133
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.... Read more
Affected Products : electric_consciousmap- EPSS Score: %8.08
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-4659
Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSC... Read more
- EPSS Score: %0.86
- Published: Jan. 19, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2019-15746
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.... Read more
Affected Products : sitos_six- EPSS Score: %0.37
- Published: Oct. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-3684
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload... Read more
Affected Products : nextgen_gallery- EPSS Score: %44.66
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-4915
Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to System Man... Read more
- EPSS Score: %2.47
- Published: Oct. 22, 2015
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2023-1283
Code Injection in GitHub repository builderio/qwik prior to 0.21.0. ... Read more
- EPSS Score: %0.31
- Published: Mar. 08, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-1424
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service... Read more
Affected Products : melsec_iq-fx5u-32mt\/es_firmware melsec_iq-fx5u-32mt\/ds_firmware melsec_iq-fx5u-32mt\/ess_firmware melsec_iq-fx5u-32mt\/dss_firmware melsec_iq-fx5u-32mr\/es_firmware melsec_iq-fx5u-32mr\/ds_firmware melsec_iq-fx5u-32mr\/ess_firmware melsec_iq-fx5u-32mr\/dss_firmware melsec_iq-fx5u-64mt\/es_firmware melsec_iq-fx5u-64mt\/ds_firmware +68 more products- EPSS Score: %1.31
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-0873
Unspecified vulnerability in the Data Server component in Oracle TimesTen In-Memory Database 7.0.6.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : timesten_in-memory_database- EPSS Score: %2.52
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025