Latest CVE Feed
-
6.1
MEDIUMCVE-2023-49258
User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at "/gui/terminal_tool.cgi" in the "data" parameter.... Read more
- EPSS Score: %0.08
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-49255
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute com... Read more
- EPSS Score: %0.08
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-47460
SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.... Read more
Affected Products : discovery- EPSS Score: %10.96
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-46942
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.... Read more
Affected Products : evershop- EPSS Score: %0.10
- Published: Jan. 13, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2023-46749
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemi... Read more
Affected Products : shiro- EPSS Score: %0.20
- Published: Jan. 15, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2023-43449
An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.... Read more
Affected Products : hummerrisk- EPSS Score: %0.16
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-34061
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.... Read more
- EPSS Score: %0.17
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-30015
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.... Read more
Affected Products : judging_management_system- EPSS Score: %0.93
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-30014
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.... Read more
Affected Products : judging_management_system- EPSS Score: %0.93
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2022-48620
uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.... Read more
Affected Products : libeuv- EPSS Score: %0.62
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2024-35057
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.... Read more
Affected Products : ait_core- Published: May. 21, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2016-20021
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.... Read more
Affected Products : portage- EPSS Score: %0.05
- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2024-35056
NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.... Read more
Affected Products : ait_core- Published: May. 21, 2024
- Modified: Jun. 03, 2025
-
8.0
HIGHCVE-2024-43027
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- Published: Aug. 21, 2024
- Modified: Jun. 03, 2025
-
6.5
MEDIUMCVE-2025-27522
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache InLong's 2.2.0 or ch... Read more
Affected Products : inlong- Published: May. 28, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-41334
Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 pri... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware vigor2620_firmware +30 more products- Published: Feb. 27, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-41338
A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware vigor2620_firmware +30 more products- Published: Feb. 27, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2024-27343
Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit th... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2024-27344
Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnera... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025
-
3.3
LOWCVE-2024-27345
Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit th... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025