CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 27d ago | 9.1 | SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application. |
| 27d ago | 9.1 | Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication. |
| Exploit 27d ago | 9.8 | OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1. |
| Exploit 27d ago | 9.8 | TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules. |
| Exploit 27d ago | 9.8 | TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg. |
| Exploit 27d ago | 9.8 | An oversight in BCB handling of reboot reason that allows for persistent code execution |
| Exploit 27d ago | 9.8 | U-Boot vulnerability resulting in persistent Code Execution |
| 27d ago | 9.8 | U-Boot shell vulnerability resulting in Privilege escalation in a production device |
| 27d ago | 9.8 | Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application |
| Exploit 27d ago | 9.1 | IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection. |
| 27d ago | 9.8 | An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface. |
| Exploit 27d ago | 9.8 | Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box. |
| 27d ago | 9.8 | An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file. |
| Exploit 27d ago | 9.8 | In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 27d ago | 9.8 | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack. |
| Exploit 27d ago | 9.8 | In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. |
| Exploit 27d ago | 9.8 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information. |
| Exploit 27d ago | 9.8 | An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the authentication function. In normal operation, the Zultys MX Administrator Windows client connects to port 7505 and attempts authentication, submitting the administrator username and password to the server. Upon authentication failure, the server sends a login failure message prompting the client to disconnect. However, if the client ignores the failure message instead and attempts to continue, the server does not forcibly close the connection and processes all subsequent requests from the client as if authentication had been successful. |
| 27d ago | 9.8 | Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. |
| Exploit 27d ago | 9.9 | Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application. |
| 27d ago | 9.6 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| Exploit 27d ago | 9.8 | Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode. |
| Exploit 27d ago | 9.8 | Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet. |
| Exploit 27d ago | 9.8 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. |
| Exploit 27d ago | 9.8 | Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet. |
| Exploit 27d ago | 9.8 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. |
| Exploit 27d ago | 9.8 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet. |
| 27d ago | 9.1 | NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability |
| 27d ago | 9.8 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. |
| 27d ago | 9.8 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. |