Latest CVE Feed
-
9.8
CRITICALCVE-2019-12585
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.... Read more
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19840
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.... Read more
Affected Products : zonedirector_1200_firmware unleashed r310 zonedirector_1200 h320 h510 r710 r720 t610 r510 +7 more products- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43457
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.... Read more
Affected Products : service_provider_management_system- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31719
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.... Read more
Affected Products : fuxa- Published: Sep. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40922
kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().... Read more
Affected Products : kerawen- Published: Nov. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23638
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo ... Read more
Affected Products : dubbo- Published: Mar. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41418
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.... Read more
Affected Products : ariang- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37800
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11082
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to log... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10625
WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.... Read more
Affected Products : webaccess\/nms- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18693
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. There is a buffer overflow in the fps sysfs entry. The Samsung ID is SVE-2016-7510 (January 2017).... Read more
Affected Products : android- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0391
The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.... Read more
- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2018-18242
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.... Read more
Affected Products : youke_365- Published: Oct. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24167
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0682
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.... Read more
- Published: Nov. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0779
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : tomee- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-21833
An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger... Read more
Affected Products : imagegear- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18394
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.... Read more
Affected Products : thingspro- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41659
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.... Read more
Affected Products : banking_system- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5187
An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. ... Read more
Affected Products : imagegear- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024