Latest CVE Feed
-
7.5
HIGHCVE-2018-18066
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.... Read more
- EPSS Score: %0.59
- Published: Oct. 08, 2018
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2018-15965
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- EPSS Score: %40.11
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
7.5
HIGHCVE-2018-15964
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to information disclosure.... Read more
Affected Products : coldfusion- EPSS Score: %10.65
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
5.3
MEDIUMCVE-2018-15963
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.... Read more
Affected Products : coldfusion- EPSS Score: %6.20
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
5.3
MEDIUMCVE-2018-15962
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information disclosure.... Read more
Affected Products : coldfusion- EPSS Score: %2.30
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2018-15959
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- EPSS Score: %40.11
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2018-15958
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- EPSS Score: %40.11
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2018-15957
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- EPSS Score: %60.60
- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
5.5
MEDIUMCVE-2018-1002205
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : dotnetzip.semverd- EPSS Score: %0.52
- Published: Jul. 25, 2018
- Modified: May. 06, 2025
-
6.1
MEDIUMCVE-2018-1000874
PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distributed parsers allowing a malicious crafted script to be executed that can result in the lose of user data and sensitive user information. T... Read more
Affected Products : markdown- EPSS Score: %0.22
- Published: Dec. 20, 2018
- Modified: May. 06, 2025
-
8.8
HIGHCVE-2017-9633
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti ... Read more
Affected Products : s-gold_2_pmb_8876- EPSS Score: %0.64
- Published: Aug. 07, 2017
- Modified: May. 06, 2025
-
5.6
MEDIUMCVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.... Read more
Affected Products : ubuntu_linux debian_linux hci_management_node solidfire vm_virtualbox communications_diameter_signaling_router core_i3 core_i5 core_i7 xeon_e3 +211 more products- EPSS Score: %90.66
- Published: Jan. 04, 2018
- Modified: May. 06, 2025
-
6.1
MEDIUMCVE-2017-2285
Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : simple_custom_css_and_js- EPSS Score: %0.53
- Published: Aug. 02, 2017
- Modified: May. 06, 2025
-
9.3
HIGHCVE-2017-16368
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability leads to a stack-based buffer overflow... Read more
- EPSS Score: %18.40
- Published: Dec. 09, 2017
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2017-14429
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell me... Read more
- EPSS Score: %3.41
- Published: Sep. 13, 2017
- Modified: May. 06, 2025
-
7.1
HIGHCVE-2024-13864
The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : countdown_timer- Published: Mar. 11, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13419
Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for auth... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3890
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user... Read more
Affected Products : wordpress_simple_paypal_shopping_cart- Published: May. 01, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
8.2
HIGHCVE-2024-4856
The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthentic... Read more
Affected Products : fs_product_inquiry- Published: Jun. 04, 2024
- Modified: May. 06, 2025
-
8.5
HIGHCVE-2024-21678
This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims b... Read more
- Published: Feb. 20, 2024
- Modified: May. 06, 2025