Latest CVE Feed
-
9.9
CRITICALCVE-2023-25915
Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.... Read more
- Published: Aug. 21, 2023
- Modified: Jan. 17, 2025
-
9.9
CRITICALCVE-2023-26055
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability ... Read more
- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-28110
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes clu... Read more
- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-10328
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.... Read more
Affected Products : pipeline_remote_loader- Published: May. 31, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-1003030
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on ... Read more
- Actively Exploited
- Published: Mar. 08, 2019
- Modified: Feb. 20, 2025
-
9.9
CRITICALCVE-2019-1003029
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroov... Read more
- Actively Exploited
- Published: Mar. 08, 2019
- Modified: Feb. 20, 2025
-
9.9
CRITICALCVE-2021-21477
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads... Read more
Affected Products : commerce- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-22946
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-... Read more
Affected Products : spark- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-22651
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security ... Read more
- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
9.9
CRITICALCVE-2016-9269
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary com... Read more
Affected Products : interscan_web_security_virtual_appliance- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2018-18406
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE v... Read more
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-12892
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-29972
Server-Side Request Forgery (SSRF) in Azure allows an authorized attacker to perform spoofing over a network.... Read more
- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2019-2253
Buffer over-read can occur while parsing an ogg file with a corrupted comment block. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon W... Read more
Affected Products : sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9150_firmware qcs605_firmware sd_675_firmware +76 more products- Published: Jul. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49959
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST reques... Read more
Affected Products : profinet-inspektor_nt- Published: Feb. 26, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-6677
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection.This issue affects Online Collection: before v.1.0.2. ... Read more
Affected Products : online_collection- Published: Feb. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19740
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.... Read more
Affected Products : oempro- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12585
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.... Read more
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19840
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.... Read more
Affected Products : zonedirector_1200_firmware unleashed r310 zonedirector_1200 h320 h510 r710 r720 t610 r510 +7 more products- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43457
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.... Read more
Affected Products : service_provider_management_system- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024