Latest CVE Feed
-
9.8
CRITICALCVE-2019-9047
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.... Read more
Affected Products : gorose- Published: Feb. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9227
An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be written into the opt_base.inc.php file.... Read more
Affected Products : baigo_cms- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-35245
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.... Read more
Affected Products : flamingo- Published: Dec. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9623
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.... Read more
Affected Products : feng_office- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9618
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.... Read more
Affected Products : gracemedia_media_player- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-35926
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.... Read more
Affected Products : nanorand- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-36052
Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.... Read more
Affected Products : minicms- Published: Jan. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-35866
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor.... Read more
Affected Products : rusqlite- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-3479
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.... Read more
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-2781
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To tr... Read more
Affected Products : matrixssl- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-36639
A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affects the function cmdVoteMap of the file plugins/adminvote.sma of the component Console Command Handler. The manipulation of the argumen... Read more
- Published: Jan. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-36640
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.jav... Read more
Affected Products : webservice_connector- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10547
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored n... Read more
Affected Products : rconfig- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14071
The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10914
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The is... Read more
Affected Products : one- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-5062
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.... Read more
Affected Products : aternity- Published: Sep. 29, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2020-5307
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the Pr... Read more
Affected Products : dairy_farm_shop_management_system- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5544
Null Pointer Dereference vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially... Read more
- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5624
SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : xoonips- Published: Aug. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6140
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not completed.... Read more
Affected Products : email_security- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024