Latest CVE Feed
-
9.9
CRITICALCVE-2017-16326
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-16328
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-16329
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-16333
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-16335
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-22579
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.... Read more
Affected Products : sequelize- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-26471
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restric... Read more
Affected Products : xwiki- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-29518
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root ca... Read more
Affected Products : xwiki- Published: Apr. 19, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-29522
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestrict... Read more
Affected Products : xwiki- Published: Apr. 19, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-30898
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All... Read more
Affected Products : siveillance_video- Published: May. 09, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-4360
The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator... Read more
Affected Products : controlled_admin_access- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-25911
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.... Read more
- Published: Jun. 11, 2023
- Modified: Jan. 17, 2025
-
9.9
CRITICALCVE-2023-35166
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-r... Read more
Affected Products : xwiki- Published: Jun. 20, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-36460
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitra... Read more
Affected Products : mastodon- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-40020
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the... Read more
Affected Products : privateuploader- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-40177
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus effectively perfor... Read more
Affected Products : xwiki- Published: Aug. 23, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-5223
A vulnerability, which was classified as critical, has been found in HimitZH HOJ up to 4.6-9a65e3f. This issue affects some unknown processing of the component Topic Handler. The manipulation leads to sandbox issue. The attack may be initiated remotely. T... Read more
Affected Products : hcode_online_judge- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-30841
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.... Read more
Affected Products : countdown_builder- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2023-20048
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is manag... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 26, 2024
-
9.9
CRITICALCVE-2023-45163
The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM pe... Read more
Affected Products : platform- Published: Nov. 06, 2023
- Modified: Jun. 12, 2025