Latest CVE Feed
-
9.8
CRITICALCVE-2020-29376
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. There is an !j@l#y$z%x6x7q8c9z) password for the admin account to authenticate to the TELNET... Read more
- Published: Nov. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8395
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.... Read more
Affected Products : manageengine_servicedesk_plus- Published: Feb. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4451
gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.... Read more
Affected Products : gitolite- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20560
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The BIOSUB Trustlet has an out of bounds write. The Samsung ID is SVE-2019-15261 (October 2019).... Read more
Affected Products : android- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9584
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access cont... Read more
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9626
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.... Read more
Affected Products : phpshe- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9629
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).... Read more
Affected Products : nexus_repository_manager- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4621
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities... Read more
Affected Products : magnolia_cms- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0235
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "str... Read more
Affected Products : android- Published: Jun. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-3577
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.... Read more
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18337
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp an... Read more
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10885
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hand... Read more
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5413
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" explo... Read more
Affected Products : retail_customer_management_and_segmentation_foundation flexcube_private_banking retail_merchandising_system banking_virtual_account_management banking_corporate_lending_process_management banking_credit_facilities_process_management banking_supply_chain_finance spring_integration- Published: Jul. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5841
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.... Read more
Affected Products : opmon- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14389
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.... Read more
Affected Products : joyplus-cms- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-6174
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.... Read more
Affected Products : the_update_framework- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6713
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_con... Read more
Affected Products : thinkcmf- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6805
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.... Read more
Affected Products : s-cms- Published: Jan. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14441
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.... Read more
Affected Products : ssh_companywebsite- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6957
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integra... Read more
- Published: May. 29, 2019
- Modified: Nov. 21, 2024