Latest CVE Feed
-
9.8
CRITICALCVE-2024-52295
DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2... Read more
Affected Products : dataease- Published: Nov. 13, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2015-0537
Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-C Micro Edition (Crypto-C ME) before 4.0.4 and 4.1, and RSA BSAFE SSL-C 2.8.9 and earlier allows... Read more
- EPSS Score: %2.28
- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2018-19061
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.... Read more
Affected Products : dedecms- EPSS Score: %0.60
- Published: Nov. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15439
A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected so... Read more
Affected Products : sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware sf300-24mp_firmware +218 more products- EPSS Score: %1.26
- Published: Nov. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6491
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.... Read more
Affected Products : ucmdb_configuration_manager- EPSS Score: %0.14
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5495
All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node.... Read more
Affected Products : storagegrid_webscale- EPSS Score: %0.74
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19281
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.... Read more
Affected Products : centreon- EPSS Score: %0.22
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7359
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which may allow an attacker to execute arbitrary code.... Read more
- EPSS Score: %0.81
- Published: Nov. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18796
Library Management System 1.0 has SQL Injection via the "Search for Books" screen.... Read more
Affected Products : library_management_system- EPSS Score: %0.25
- Published: Nov. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18805
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.... Read more
Affected Products : pointofsales- EPSS Score: %4.62
- Published: Nov. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9209
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2... Read more
Affected Products : php-traditional-server- EPSS Score: %1.94
- Published: Nov. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-16223
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application through 1.0.5 for Android allows an attacker to retrieve the username and password.... Read more
Affected Products : qbeecam- EPSS Score: %0.80
- Published: Nov. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19410
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directi... Read more
Affected Products : prtg_network_monitor- Actively Exploited
- EPSS Score: %93.12
- Published: Nov. 21, 2018
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2018-17934
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or ... Read more
Affected Products : nuuo_cms- EPSS Score: %67.75
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19290
In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the PHP daemon with a crafted command, resulting in a denial of service or possibly unspecified other impact,... Read more
Affected Products : budabot- EPSS Score: %2.95
- Published: Nov. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14703
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.... Read more
- EPSS Score: %2.04
- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33025
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.... Read more
Affected Products : wcd9380_firmware wcn3988_firmware wsa8810_firmware wsa8815_firmware wsa8830_firmware wsa8835_firmware ar8035_firmware qca8081_firmware qca8337_firmware qcm4490_firmware +38 more products- EPSS Score: %0.16
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20056
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowing remote attackers to execute arbitrary code without authentication via the goform/formLanguageChange curr... Read more
- EPSS Score: %46.44
- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1818
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 15... Read more
Affected Products : security_guardium- EPSS Score: %0.04
- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.42
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024