Latest CVE Feed
-
9.9
CRITICALCVE-2023-30838
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence o... Read more
Affected Products : prestashop- EPSS Score: %0.52
- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-10396
Vulnerability in the Oracle Hospitality Cruise AffairWhere component of Oracle Hospitality Applications (subcomponent: AffairWhere). Supported versions that are affected are 2.2.5.0, 2.2.6.0 and 2.2.7.0. Easily exploitable vulnerability allows low privile... Read more
Affected Products : hospitality_cruise_affairwhere- EPSS Score: %0.44
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-2866
An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.... Read more
- EPSS Score: %1.30
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-2898
An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney. Specially crafted network packets can cause an unsigned firmware to be installed in the device resulting in arbitrary code execut... Read more
- EPSS Score: %0.51
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-2917
An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.... Read more
- EPSS Score: %1.32
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2021-4347
The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level... Read more
Affected Products : advanced_shipment_tracking_for_woocommerce- EPSS Score: %0.09
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-4368
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it p... Read more
Affected Products : frontend_file_manager_plugin- EPSS Score: %5.21
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-32232
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated p... Read more
Affected Products : printerlogic_client- EPSS Score: %0.46
- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-4195
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.... Read more
Affected Products : cockpit- EPSS Score: %1.64
- Published: Aug. 06, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-3710
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printer... Read more
- EPSS Score: %91.68
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-5183
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker ... Read more
Affected Products : core_policy_compute_engine- EPSS Score: %0.60
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-43651
JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. This vulnerability may further be leveraged to gain root privileges on the sy... Read more
Affected Products : jumpserver- EPSS Score: %13.92
- Published: Sep. 27, 2023
- Modified: Mar. 25, 2025
-
9.9
CRITICALCVE-2023-37909
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arbitrary script ma... Read more
Affected Products : xwiki- EPSS Score: %10.46
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-37912
XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes`... Read more
- EPSS Score: %9.89
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-5199
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to incl... Read more
Affected Products : php_to_page- EPSS Score: %4.86
- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-46404
PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.... Read more
Affected Products : pcrs- EPSS Score: %40.84
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-55662
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on th... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
9.9
CRITICALCVE-2024-54262
Unrestricted Upload of File with Dangerous Type vulnerability in Siddharth Nagar Import Export For WooCommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through 1.5.... Read more
Affected Products : import_export_for_woocommerce- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.9
CRITICALCVE-2024-56050
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.3.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.9
CRITICALCVE-2021-21480
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard ... Read more
Affected Products : manufacturing_integration_and_intelligence- EPSS Score: %25.93
- Published: Mar. 09, 2021
- Modified: May. 05, 2025