Latest CVE Feed
-
9.9
CRITICALCVE-2022-1770
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.... Read more
Affected Products : trudesk- EPSS Score: %0.28
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-40358
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (... Read more
- EPSS Score: %0.58
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-43684
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to P... Read more
Affected Products : servicenow- EPSS Score: %0.22
- Published: Jun. 13, 2023
- Modified: Feb. 13, 2025
-
9.9
CRITICALCVE-2023-31090
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widg... Read more
- Published: Apr. 24, 2024
- Modified: Feb. 05, 2025
-
9.9
CRITICALCVE-2023-35152
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. Leading to rights... Read more
Affected Products : xwiki- EPSS Score: %0.91
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-40029
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotatio... Read more
- EPSS Score: %0.69
- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-4037
Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.... Read more
Affected Products : conacwin- EPSS Score: %0.04
- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-23619
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/or does not hand... Read more
Affected Products : modelina- EPSS Score: %0.22
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-27874
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.... Read more
- EPSS Score: %0.14
- Published: Mar. 21, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-51417
Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3. ... Read more
Affected Products : jvm_gutenberg_rich_text_icons- EPSS Score: %0.66
- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-37425
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.... Read more
- EPSS Score: %4.60
- Published: Oct. 28, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-25311
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.... Read more
Affected Products : htcondor- EPSS Score: %2.77
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-1644
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. ... Read more
Affected Products : suitecrm- Published: Feb. 20, 2024
- Modified: Dec. 31, 2024
-
9.9
CRITICALCVE-2024-27972
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Very Good Plugins WP Fusion Lite allows Command Injection.This issue affects WP Fusion Lite: from n/a through 3.41.24. ... Read more
Affected Products : wp_fusion- Published: Apr. 03, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-8767
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis... Read more
Affected Products :- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
9.9
CRITICALCVE-2023-29214
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper e... Read more
Affected Products : xwiki- EPSS Score: %7.12
- Published: Apr. 16, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-8621
The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of ... Read more
Affected Products : daily_prayer_time- Published: Sep. 25, 2024
- Modified: Oct. 02, 2024
-
9.9
CRITICALCVE-2024-36393
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Read more
Affected Products : sysaid- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-41799
tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. These .d... Read more
Affected Products : tgstation-server- Published: Jul. 29, 2024
- Modified: Aug. 19, 2025
-
9.9
CRITICALCVE-2018-3832
An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS binaries that could be modified to enable access to hidden resources which allow for uploading unsigned f... Read more
- EPSS Score: %0.42
- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024