CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 9.8 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. |
| 1mo ago | 9.8 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. |
| 1mo ago | 9.8 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. |
| 1mo ago | 9.8 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. |
| Exploit 1mo ago | 9.1 | Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it. |
| Exploit 1mo ago | 9.1 | MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php. |
| Exploit 1mo ago | 9.8 | The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input. |
| Exploit 1mo ago | 9.8 | An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter. |
| 1mo ago | 9.8 | IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313. |
| 1mo ago | 9.8 | Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization. |
| Exploit 1mo ago | 9.8 | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh. |
| Exploit 1mo ago | 9.8 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. |
| Exploit 1mo ago | 9.8 | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh. |
| Exploit 1mo ago | 9.8 | Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code. |
| Exploit 1mo ago | 9.8 | Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. |
| Exploit 1mo ago | 9.8 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php. |
| Exploit 1mo ago | 9.8 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh. |
| Exploit 1mo ago | 9.8 | Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. |
| 1mo ago | 9.1 | On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges. |
| Exploit 1mo ago | 9.1 | Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files. |
| 1mo ago | 9.9 | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. |
| 1mo ago | 9.1 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
| 1mo ago | 9.1 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability. |
| 1mo ago | 9.8 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
| 1mo ago | 9.8 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
| 1mo ago | 9.8 | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
| 1mo ago | 9.1 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
| 1mo ago | 9.1 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
| 1mo ago | 9.8 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
| 1mo ago | 9.1 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |