Latest CVE Feed
-
9.9
CRITICALCVE-2024-29202
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Cele... Read more
Affected Products : jumpserver- Published: Mar. 29, 2024
- Modified: Mar. 25, 2025
-
9.9
CRITICALCVE-2024-25918
Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP Team InstaWP Connect allows Code Injection.This issue affects InstaWP Connect: from n/a through 0.1.0.8. ... Read more
Affected Products : instawp_connect- Published: Apr. 03, 2024
- Modified: Feb. 09, 2025
-
9.9
CRITICALCVE-2024-32514
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4. ... Read more
Affected Products : wp_poll_maker- Published: Apr. 17, 2024
- Modified: Jun. 09, 2025
-
9.9
CRITICALCVE-2023-32713
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and includ... Read more
Affected Products : splunk_app_for_stream- EPSS Score: %0.16
- Published: Jun. 01, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-33318
Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40. ... Read more
Affected Products : automatewoo- EPSS Score: %0.31
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-1698
Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.... Read more
Affected Products : organizr- EPSS Score: %0.30
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-3549
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of... Read more
Affected Products : blog2social- Published: Jun. 11, 2024
- Modified: Jun. 05, 2025
-
9.9
CRITICALCVE-2018-3874
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 32 bytes. An atta... Read more
- EPSS Score: %0.38
- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-42480
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other con... Read more
Affected Products : kamaji- Published: Aug. 12, 2024
- Modified: Aug. 16, 2024
-
9.9
CRITICALCVE-2023-39420
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this r... Read more
Affected Products : internet_reservation_module_next_generation- EPSS Score: %0.30
- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-29512
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access ... Read more
Affected Products : xwiki- EPSS Score: %2.15
- Published: Apr. 19, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-36469
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros that all... Read more
Affected Products : xwiki- EPSS Score: %47.07
- Published: Jun. 29, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-40050
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution. ... Read more
Affected Products : automate- EPSS Score: %9.89
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-29205
XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able ... Read more
Affected Products : xwiki- EPSS Score: %2.31
- Published: Apr. 15, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-46642
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.... Read more
- EPSS Score: %1.87
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
9.9
CRITICALCVE-2023-38052
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.... Read more
Affected Products : easyappointments- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-4872
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must ha... Read more
- Published: Aug. 27, 2024
- Modified: Oct. 30, 2024
-
9.9
CRITICALCVE-2024-21663
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without ... Read more
Affected Products : discord-recon- EPSS Score: %1.34
- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-52427
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.... Read more
Affected Products : event_tickets_with_ticket_scanner- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.9
CRITICALCVE-2024-49653
Unrestricted Upload of File with Dangerous Type vulnerability in James Eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through 1.2.... Read more
Affected Products :- Published: Oct. 23, 2024
- Modified: Oct. 25, 2024