Latest CVE Feed
-
9.8
CRITICALCVE-2022-23088
The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may ove... Read more
Affected Products : freebsd- Published: Feb. 15, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22922
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php... Read more
Affected Products : visitor_management_system_in_php- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
8.8
HIGHCVE-2024-22903
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.... Read more
Affected Products : vinchin_backup_and_recovery- Published: Feb. 02, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22729
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.... Read more
- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
6.1
MEDIUMCVE-2024-22725
Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.... Read more
Affected Products : orthanc- Published: Jan. 24, 2024
- Modified: Jun. 04, 2025
-
7.2
HIGHCVE-2024-22625
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.... Read more
Affected Products : supplier_management_system- Published: Jan. 16, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22529
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.... Read more
- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
6.1
MEDIUMCVE-2024-22048
govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page. ... Read more
Affected Products : govuk_tech_docs- Published: Jan. 04, 2024
- Modified: Jun. 04, 2025
-
7.1
HIGHCVE-2020-16247
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
6.3
MEDIUMCVE-2020-16241
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.... Read more
- Published: Aug. 21, 2020
- Modified: Jun. 04, 2025
-
4.9
MEDIUMCVE-2020-16239
When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.... Read more
- Published: Aug. 21, 2020
- Modified: Jun. 04, 2025
-
2.1
LOWCVE-2020-16237
Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.... Read more
- Published: Aug. 21, 2020
- Modified: Jun. 04, 2025
-
6.5
MEDIUMCVE-2020-16200
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the e... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
6.3
MEDIUMCVE-2020-16198
When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct.... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
3.5
LOWCVE-2020-14525
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
5.3
MEDIUMCVE-2020-14518
Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.... Read more
Affected Products : dreammapper- Published: Aug. 21, 2020
- Modified: Jun. 04, 2025
-
4.4
MEDIUMCVE-2020-14477
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternat... Read more
Affected Products : clearvue_850_firmware clearvue_350_firmware cx50_firmware affiniti_70_firmware affiniti_50_firmware epiq_7_firmware sparq_firmware xperius_firmware clearvue_850 clearvue_350 +6 more products- Published: Jun. 26, 2020
- Modified: Jun. 04, 2025
-
4.5
MEDIUMCVE-2020-12023
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) a... Read more
Affected Products : intellibridge_enterprise- Published: Jun. 11, 2020
- Modified: Jun. 04, 2025
-
6.5
MEDIUMCVE-2022-23093
ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a "quoted packet," which represents the packet that generate... Read more
Affected Products : freebsd- Published: Feb. 15, 2024
- Modified: Jun. 04, 2025
-
8.8
HIGHCVE-2022-23092
The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the receipt of a specially crafted message will cause lib9p to overwrite unrelated memory. The b... Read more
Affected Products : freebsd- Published: Feb. 15, 2024
- Modified: Jun. 04, 2025