Latest CVE Feed
-
9.9
CRITICALCVE-2024-39714
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.... Read more
Affected Products : veeam_service_provider_console- Published: Sep. 07, 2024
- Modified: Sep. 09, 2024
-
9.9
CRITICALCVE-2018-18406
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE v... Read more
- EPSS Score: %0.73
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-16281
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- EPSS Score: %0.08
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-1969
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.... Read more
Affected Products : security_identity_manager- EPSS Score: %0.38
- Published: Jan. 14, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-13478
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.... Read more
Affected Products : yoast_seo- EPSS Score: %0.26
- Published: Jul. 09, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-26943
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python ev... Read more
Affected Products : blazar-dashboard- EPSS Score: %1.52
- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-11011
In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.... Read more
Affected Products : phproject- EPSS Score: %0.90
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-29068
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7000 before 1.0.11.106, R6900P before 1.3.2.124, R7000P before 1.3.2.124, R7900 before 1.0.4.26, R7850 befo... Read more
Affected Products : r7800_firmware r6120_firmware r6220_firmware r6260_firmware r6700_firmware r6800_firmware r6900_firmware r6900p_firmware r7000_firmware r7000p_firmware +150 more products- EPSS Score: %0.55
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-3880
An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles exis... Read more
- EPSS Score: %0.29
- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-1509
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.... Read more
Affected Products : control_panel- EPSS Score: %1.68
- Published: Apr. 28, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-20779
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host t... Read more
Affected Products : enterprise_nfv_infrastructure_software- EPSS Score: %2.34
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-21276
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allow... Read more
Affected Products : communications_billing_and_revenue_management- EPSS Score: %1.66
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-3925
An exploitable buffer overflow vulnerability exists in the remote video-host communication of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process insecurely parses the AWSELB cookie... Read more
- EPSS Score: %0.42
- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-35049
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results i... Read more
- EPSS Score: %3.37
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-43821
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and ... Read more
Affected Products : opencast- EPSS Score: %1.04
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-41928
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. T... Read more
Affected Products : xwiki- EPSS Score: %0.94
- Published: Nov. 23, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-28444
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during bui... Read more
Affected Products : angular-server-side-configuration- EPSS Score: %0.06
- Published: Mar. 24, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-29523
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution i... Read more
Affected Products : xwiki- EPSS Score: %14.36
- Published: Apr. 19, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-36470
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that is executed with... Read more
Affected Products : xwiki- EPSS Score: %14.17
- Published: Jun. 29, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-46623
Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2. ... Read more
Affected Products : wp_extra- EPSS Score: %0.21
- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024