Latest CVE Feed
-
10.0
CRITICALCVE-2023-2825
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least... Read more
Affected Products : gitlab- EPSS Score: %93.16
- Published: May. 26, 2023
- Modified: Jan. 15, 2025
-
10.0
HIGHCVE-2022-31800
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.... Read more
- EPSS Score: %1.98
- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2022-27625
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified ... Read more
- EPSS Score: %1.46
- Published: Oct. 20, 2022
- Modified: Jan. 14, 2025
-
10.0
HIGHCVE-2022-24292
Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.... Read more
Affected Products : laserjet_pro_m304-m305_w1a46a_firmware laserjet_pro_m304-m305_w1a47a_firmware laserjet_pro_m304-m305_w1a48a_firmware laserjet_pro_m304-m305_w1a66a_firmware laserjet_pro_m404-m405_93m22a_firmware laserjet_pro_m453-m454_w1y40a_firmware laserjet_pro_m453-m454_w1y41a_firmware laserjet_pro_m453-m454_w1y43a_firmware laserjet_pro_m453-m454_w1y44a_firmware laserjet_pro_m453-m454_w1y45a_firmware +126 more products- EPSS Score: %8.52
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-2274
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will h... Read more
Affected Products : h410c_firmware snapcenter openssl h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s +2 more products- EPSS Score: %52.02
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-44515
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise bu... Read more
Affected Products : manageengine_desktop_central- Actively Exploited
- EPSS Score: %94.31
- Published: Dec. 12, 2021
- Modified: Mar. 14, 2025
-
10.0
CRITICALCVE-2021-4140
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.... Read more
- EPSS Score: %0.05
- Published: Dec. 22, 2022
- Modified: Apr. 16, 2025
-
10.0
CRITICALCVE-2021-38503
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < ... Read more
- EPSS Score: %1.39
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-33796
In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service. ... Read more
Affected Products : mujs- EPSS Score: %0.08
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-33045
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.... Read more
Affected Products : ipc-hum7xxx_firmware ipc-hx3xxx_firmware ipc-hx5xxx_firmware vto-65xxx_firmware vto-75x95x_firmware vth-542xh_firmware nvr-1xxx_firmware nvr-2xxx_firmware nvr-4xxx_firmware nvr-5xxx_firmware +26 more products- Actively Exploited
- EPSS Score: %94.12
- Published: Sep. 15, 2021
- Modified: Feb. 24, 2025
-
10.0
HIGHCVE-2021-32802
Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited for untrusted user... Read more
- EPSS Score: %0.91
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-23281
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a speci... Read more
Affected Products : intelligent_power_manager- EPSS Score: %0.58
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-22893
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform... Read more
- Actively Exploited
- EPSS Score: %93.51
- Published: Apr. 23, 2021
- Modified: Mar. 21, 2025
-
10.0
HIGHCVE-2021-1829
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.... Read more
Affected Products : macos- EPSS Score: %0.84
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-1479
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about th... Read more
- EPSS Score: %2.57
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8445
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitte... Read more
Affected Products : ossec- EPSS Score: %0.99
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-7007
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of service.... Read more
- EPSS Score: %0.41
- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-5344
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitra... Read more
Affected Products : idrac9_firmware idrac8_firmware idrac7_firmware emc_idrac9_firmware idrac7 idrac8 idrac9- EPSS Score: %7.54
- Published: Mar. 31, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3992
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi ma... Read more
- Actively Exploited
- EPSS Score: %90.92
- Published: Oct. 20, 2020
- Modified: Apr. 02, 2025
-
10.0
HIGHCVE-2020-3586
A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied i... Read more
Affected Products : dna_spaces\- EPSS Score: %2.23
- Published: Nov. 18, 2020
- Modified: Nov. 21, 2024