Latest CVE Feed
-
9.8
CRITICALCVE-2019-15039
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.... Read more
Affected Products : teamcity- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14819
Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-47218
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.... Read more
Affected Products : nebulagraph_database- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33374
Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.... Read more
Affected Products :- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-38395
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."... Read more
Affected Products : iterm2- Published: Jun. 16, 2024
- Modified: Jun. 18, 2025
-
9.8
CRITICALCVE-2022-41217
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.... Read more
Affected Products : cloudflow- Published: Feb. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-46374
Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.... Read more
Affected Products : best_house_rental_management_system- Published: Sep. 18, 2024
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2022-3089
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used t... Read more
- Published: Feb. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39177
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can connect to the server to forge a LoginPacket with manipulated JWT token allowing impersonation as any user.... Read more
Affected Products : geyser- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23795
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.... Read more
Affected Products : joomla\!- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45756
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16232
In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.... Read more
Affected Products : widefield3- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14982
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.... Read more
- Published: Aug. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-20392
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.... Read more
Affected Products : imcat- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10651
An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 SU3, with remote code execution. In other words, the issue affects 2017.3, 2018.1, and 2018.3 installations that lack the April 2019 upd... Read more
Affected Products : endpoint_manager- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12196
A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.... Read more
Affected Products : manageengine_netflow_analyzer- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29045
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.... Read more
Affected Products : five_star_restaurant_menu- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2160
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0. ... Read more
Affected Products : modoboa- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-47213
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR... Read more
Affected Products : cfr-1004ea_firmware cfr-1008ea_firmware cfr-1016ea_firmware cfr-16eaa_firmware cfr-16eab_firmware cfr-16eha_firmware cfr-16ehd_firmware cfr-4eaa_firmware cfr-4eaam_firmware cfr-4eab_firmware +46 more products- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-36108
casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR #201 which is pe... Read more
Affected Products :- Published: May. 31, 2024
- Modified: Nov. 21, 2024