Latest CVE Feed
-
9.9
CRITICALCVE-2017-16275
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- EPSS Score: %0.08
- Published: Jan. 11, 2023
- Modified: Apr. 09, 2025
-
9.9
CRITICALCVE-2018-1789
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.... Read more
Affected Products : api_connect- EPSS Score: %0.18
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-6262
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the ... Read more
Affected Products : application_server- EPSS Score: %0.79
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2016-8355
An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user elevated privileges on the SQL database, which would allow an authenticated... Read more
Affected Products : cadd-solis_medication_safety_software- EPSS Score: %0.39
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2016-9832
PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated... Read more
Affected Products : ace-advanced_business_application_programming- EPSS Score: %7.26
- Published: Dec. 10, 2016
- Modified: Apr. 12, 2025
-
9.9
CRITICALCVE-2015-7411
The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.... Read more
Affected Products : tivoli_monitoring- EPSS Score: %0.79
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
9.9
CRITICALCVE-2017-7175
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).... Read more
Affected Products : nfsen- EPSS Score: %21.42
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2018-18555
A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuing various shell special characters with certain commands, an authenticated operator user can break out of ... Read more
Affected Products : vyos- EPSS Score: %1.45
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-17536
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.... Read more
Affected Products : gila_cms- EPSS Score: %0.42
- Published: Oct. 13, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2013-3960
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass... Read more
Affected Products : easy_file_manager- EPSS Score: %0.68
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-27483
Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ application to the ConnectIQ store. The ConnectIQ prog... Read more
- EPSS Score: %2.36
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-6081
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to... Read more
Affected Products : runtime- EPSS Score: %0.86
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-8992
The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Ac... Read more
- EPSS Score: %0.72
- Published: Apr. 24, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-16096
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system... Read more
Affected Products : command_centre- EPSS Score: %0.22
- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-11075
In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can on... Read more
Affected Products : engine- EPSS Score: %1.06
- Published: May. 27, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-26753
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all a... Read more
Affected Products : nedi- EPSS Score: %0.58
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-3896
An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON pa... Read more
- EPSS Score: %0.22
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-20780
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host t... Read more
Affected Products : enterprise_nfv_infrastructure_software- EPSS Score: %2.36
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-26780
Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigg... Read more
- EPSS Score: %0.91
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-38163
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operat... Read more
Affected Products : netweaver- Actively Exploited
- EPSS Score: %88.32
- Published: Sep. 14, 2021
- Modified: Mar. 13, 2025