Latest CVE Feed
-
10.0
CRITICALCVE-2018-2913
Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Monitoring Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with... Read more
Affected Products : goldengate- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attacker... Read more
Affected Products : file_manager- Actively Exploited
- Published: Sep. 09, 2020
- Modified: Mar. 14, 2025
-
10.0
HIGHCVE-2020-2040
A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interf... Read more
Affected Products : pan-os- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-3122
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploit... Read more
Affected Products : command_center_agent- Published: Feb. 07, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-1615
The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these default credentials by the administrator, an attacker could exploit these credentials and access the vMX i... Read more
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-15639
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the decryptFile method of th... Read more
Affected Products : qconvergeconsole- Published: Aug. 25, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-14859
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthentica... Read more
Affected Products : weblogic_server- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-13802
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.... Read more
Affected Products : rebar3- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-1483
Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.... Read more
Affected Products : clientless_vpn_gateway_4400- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2018-2611
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: Core Services). The supported version that is affected is Prior to 8.7.13. Easily exploitable vulnerability allows unauthenticated attack... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-9505
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenticated attacker may be able to remotely execute arbitrary... Read more
Affected Products : print_management- Published: May. 08, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-1463
Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1770
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.... Read more
Affected Products : cpanel- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-7838
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7098
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7091
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-1280
The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename.... Read more
Affected Products : junkie_ftp_client- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1283
Buffer overflow in the Mesh::type method in mesh.c for the mview program in Mesh Viewer 0.2.2 allows remote attackers to execute arbitrary code via crafted mesh files.... Read more
Affected Products : mesh_viewer- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-3980
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload... Read more
Affected Products : dameware_mini_remote_control- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-1273
Buffer overflow in the DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a long filename.... Read more
Affected Products : greed- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025