Latest CVE Feed
-
9.9
CRITICALCVE-2024-34411
Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0. ... Read more
Affected Products : canvasio3d_light- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2015-2079
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.... Read more
- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
9.9
CRITICALCVE-2024-32514
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4. ... Read more
Affected Products : wp_poll_maker- Published: Apr. 17, 2024
- Modified: Jun. 09, 2025
-
9.9
CRITICALCVE-2019-5153
An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in re... Read more
- EPSS Score: %1.32
- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-35762
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution. ... Read more
- EPSS Score: %0.43
- Published: Nov. 20, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-31997
XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the user'... Read more
Affected Products : xwiki- Published: Apr. 10, 2024
- Modified: Jan. 09, 2025
-
9.9
CRITICALCVE-2020-15049
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+... Read more
- EPSS Score: %2.10
- Published: Jun. 30, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-31390
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2. ... Read more
Affected Products : breakdance- Published: Apr. 03, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-4077
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using both `contextIs... Read more
Affected Products : electron- EPSS Score: %0.44
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-9463
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API ... Read more
- Actively Exploited
- Published: Oct. 09, 2024
- Modified: Nov. 15, 2024
-
9.9
CRITICALCVE-2022-43402
A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including ... Read more
Affected Products : pipeline\- EPSS Score: %0.07
- Published: Oct. 19, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-2083
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypas... Read more
Affected Products : zenml- Published: Apr. 16, 2024
- Modified: May. 12, 2025
-
9.9
CRITICALCVE-2024-29201
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container... Read more
Affected Products : jumpserver- Published: Mar. 29, 2024
- Modified: Mar. 25, 2025
-
9.9
CRITICALCVE-2024-29202
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Cele... Read more
Affected Products : jumpserver- Published: Mar. 29, 2024
- Modified: Mar. 25, 2025
-
9.9
CRITICALCVE-2020-27134
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive info... Read more
- EPSS Score: %0.67
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2012-1516
The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS v... Read more
- EPSS Score: %1.16
- Published: May. 04, 2012
- Modified: Apr. 11, 2025
-
9.9
CRITICALCVE-2020-2586
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker wi... Read more
Affected Products : human_resources- EPSS Score: %1.98
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2020-2587
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker wi... Read more
Affected Products : human_resources- EPSS Score: %1.98
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-18809
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Editi... Read more
Affected Products : jasperreports_server jaspersoft jaspersoft_reporting_and_analytics jasperreports_library jasperreports_library_community_edition jasperreports_library_for_activematrix_bpm jasperreports_server_community_edition jasperreports_server_for_activematrix_bpm jaspersoft_for_aws_with_multi-tenancy jaspersoft_reporting_and_analytics_for_aws- Actively Exploited
- EPSS Score: %93.96
- Published: Mar. 07, 2019
- Modified: Feb. 12, 2025
-
9.9
CRITICALCVE-2024-27956
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0. ... Read more
- Published: Mar. 21, 2024
- Modified: Feb. 14, 2025