Latest CVE Feed
-
10.0
HIGHCVE-2008-1155
Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error ... Read more
Affected Products : network_admission_control- Published: Apr. 16, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-50567
Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statemen... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2008-1154
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require au... Read more
Affected Products : unified_communications_manager emergency_responder unified_presence mobility_manager- Published: Apr. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-48148
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce allows Using Malicious Files. This issue affects StoreKeeper for WooCommerce: from n/a through 14.4.4.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
10.0
HIGHCVE-2008-1369
A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root logins in a manner unintended by the vendor, which allows remote attackers to gain privileges vi... Read more
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-9118
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.... Read more
Affected Products :- Published: Aug. 25, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Path Traversal
-
10.0
HIGHCVE-2008-1117
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination f... Read more
Affected Products : timbuktu_pro- Published: Mar. 14, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-46348
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and downl... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-32444
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization o... Read more
Affected Products : vllm- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-55169
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This... Read more
Affected Products : wegia- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2011-10017
Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell c... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2008-1049
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.... Read more
- Published: Feb. 27, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-1040
Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0.1 and 9.0.0, and Interstage Apworks 8.0.0 allows remote attackers to execute arbitrary code via a long URI.... Read more
- Published: Feb. 27, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-1030
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which... Read more
- Published: Jun. 02, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-26853
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.... Read more
- Published: Mar. 20, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2019-19897
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM context of the target system by using t... Read more
Affected Products : easyinstall- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2025-54351
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2012-10035
Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary c... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
10.0
HIGHCVE-2008-0960
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONT... Read more
Affected Products : ios solaris sunos ios_xr ace_4710 catos ingate_firewall ingate_siparator session_and_resource_control cisco_ios +15 more products- Published: Jun. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0953
The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than ... Read more
Affected Products : instant_support- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025