Latest CVE Feed
-
10.0
CRITICALCVE-2025-5243
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code In... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2014-125115
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials ... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2008-0443
Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value. NOTE: some of these detai... Read more
Affected Products : fileuploader.dll- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0437
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL... Read more
- Published: Jan. 23, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-54419
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an at... Read more
Affected Products : node_saml- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
10.0
HIGHCVE-2008-0374
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.... Read more
- Published: Jan. 22, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0380
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.... Read more
Affected Products : rtspvapgdecoder.dll- Published: Jan. 22, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0345
Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.... Read more
- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0341
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03.... Read more
Affected Products : database_server- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0344
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.... Read more
- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2019-19148
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.... Read more
- Published: Mar. 20, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-6609
libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2007-1959
Unspecified vulnerability in the process_cmdent function in command.cpp in TinyMUX before 2.4 has unknown impact and attack vectors, related to lack of the "'other half' of buffer overflow protection."... Read more
Affected Products : tinymux- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2019-19015
An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the appliance. By connecting to the database through the proxy (without password... Read more
Affected Products : webtitan- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-0510
Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors. NOTE: some of these details are obtained from third party information. NOTE: There may not be any attack vec... Read more
Affected Products : awffull- Published: Jan. 26, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0342
Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.... Read more
Affected Products : database_server- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0347
Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Or... Read more
- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0251
Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.... Read more
Affected Products : photopost_vbgallery- Published: Jan. 12, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0244
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.... Read more
Affected Products : maxdb- Published: Jan. 12, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0246
admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.... Read more
- Published: Jan. 12, 2008
- Modified: Apr. 09, 2025