Latest CVE Feed
-
9.8
CRITICALCVE-2023-4659
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE reque... Read more
Affected Products : free5gc- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-30593
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.... Read more
- Published: Mar. 28, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2019-20827
An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It allows stack consumption because of interaction between ICC-Based color space and Alternate color space.... Read more
- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-5721
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.... Read more
- Published: Sep. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-30273
The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-ciphe... Read more
Affected Products : mdlc- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52044
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.... Read more
Affected Products : elfinder- Published: Oct. 31, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICAL- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3836
dbeaver is vulnerable to Improper Restriction of XML External Entity Reference... Read more
Affected Products : dbeaver- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.... Read more
Affected Products : supersign_cms- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20032
SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially leads to Remote Code Execution. This vulnerability impacts Analytics On-Prem 2.5.2518 and earlier.... Read more
Affected Products : analytics- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14807
A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a and prior may allow remote code execution.... Read more
Affected Products : pac_control- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27469
Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).... Read more
Affected Products : monsta_ftp- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38477
There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.... Read more
Affected Products : versiondog- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22794
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)... Read more
Affected Products : struxureware_data_center_expert- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3263
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31810
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.... Read more
- Published: May. 14, 2024
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-21096
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Andr... Read more
Affected Products : android- Published: Apr. 19, 2023
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2023-46990
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.... Read more
Affected Products : publiccms- Published: Nov. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34532
A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.... Read more
Affected Products :- Published: May. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-21163
In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation... Read more
Affected Products : android- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024