Latest CVE Feed
-
10.0
HIGHCVE-2019-15310
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 bu... Read more
Affected Products : linkplay- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.... Read more
Affected Products : fedora debian_linux junos eos communications_performance_intelligence_center netkit_telnet- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-17006
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow... Read more
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-52218
Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8. ... Read more
Affected Products : woocommerce_tranzila_payment_gateway- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-15260
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain UR... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-52225
Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1. ... Read more
Affected Products : taggbox- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5635
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.... Read more
Affected Products : support_incident_tracker- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-5151
Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5617
Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1, prevents it from launching, which has unspecified impact, related to untrusted virtual machine images.... Read more
- Published: Oct. 21, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-5610
The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to delete an arbitrary file via a full pathname in the argument.... Read more
Affected Products : instant_support- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2023-51505
Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerc... Read more
Affected Products : woot- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-51438
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with ma... Read more
- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-51411
Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3. ... Read more
Affected Products : frontend_admin- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-7779
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-11563
D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions such as changing the passwords and getting basic information, was installed on the device. A remote attacker... Read more
- Published: Aug. 24, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5602
Multiple stack-based buffer overflows in SwiftView Viewer before 8.3.5, as used by SwiftView and SwiftSend, allow remote attackers to execute arbitrary code via unspecified vectors to the (1) svocx.ocx ActiveX control or the (2) npsview.dll plugin for Moz... Read more
Affected Products : viewer- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2023-51473
Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3. ... Read more
Affected Products : terraclassifieds- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.... Read more
Affected Products : webmin- Actively Exploited
- Published: Aug. 16, 2019
- Modified: Mar. 14, 2025
-
10.0
HIGHCVE-2019-15027
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in pla... Read more
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5559
Heap-based buffer overflow in the IBM ThinkVantage TPM Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it... Read more
Affected Products : thinkvantage_tpm- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025