Latest CVE Feed
-
9.9
CRITICALCVE-2021-1417
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive informa... Read more
Affected Products : jabber- EPSS Score: %0.34
- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-23120
A vulnerability allowing remote code execution (RCE) for domain users.... Read more
Affected Products : veeam_backup_\&_replication- Published: Mar. 20, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2022-43545
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V... Read more
Affected Products : 7kg9501-0aa01-2aa1_firmware 7kg9501-0aa31-2aa1_firmware 7kg9501-0aa01-2aa1 7kg9501-0aa31-2aa1- EPSS Score: %1.21
- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-3105
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of... Read more
Affected Products : woody_code_snippets- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-39932
Gogs through 0.13.0 allows argument injection during the previewing of changes.... Read more
Affected Products : gogs- Published: Jul. 04, 2024
- Modified: Apr. 10, 2025
-
9.9
CRITICALCVE-2024-39943
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of sp... Read more
Affected Products : http_file_server- Published: Jul. 04, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-39915
Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF repo... Read more
Affected Products : thruk- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-39930
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if ... Read more
Affected Products : gogs- Published: Jul. 04, 2024
- Modified: Apr. 11, 2025
-
9.9
CRITICALCVE-2024-39327
Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2024-38194
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.... Read more
Affected Products : azure_web_apps- Published: Sep. 10, 2024
- Modified: Sep. 17, 2024
-
9.9
CRITICALCVE-2024-37906
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Application. The SQL ... Read more
Affected Products : admidio- Published: Jul. 29, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-37901
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchS... Read more
Affected Products : xwiki- Published: Jul. 31, 2024
- Modified: Sep. 06, 2024
-
9.9
CRITICALCVE-2024-37288
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en... Read more
Affected Products : kibana- Published: Sep. 09, 2024
- Modified: Sep. 16, 2024
-
9.9
CRITICALCVE-2015-7926
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive information via an unspecified URL.... Read more
Affected Products : ewon_firmware- EPSS Score: %0.91
- Published: Dec. 23, 2015
- Modified: Apr. 12, 2025
-
9.9
CRITICALCVE-2015-5951
A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.... Read more
Affected Products : fatca- EPSS Score: %3.07
- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-6103
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execu... Read more
Affected Products : radeon_directx_11_driver_atidxx64.dll- EPSS Score: %0.93
- Published: Jul. 20, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-6101
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a specially crafted shader file to trigger this vulnerability, resulting in code executi... Read more
Affected Products : radeon_directx_11_driver_atidxx64.dll- EPSS Score: %0.93
- Published: Jul. 20, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-6081
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to... Read more
Affected Products : runtime- EPSS Score: %0.86
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2017-10352
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerabilit... Read more
Affected Products : weblogic_server- EPSS Score: %27.74
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2024-34762
Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Adv... Read more
Affected Products :- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024