CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 9.8 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. |
| Exploit 1mo ago | 9.8 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. |
| Exploit 1mo ago | 9.8 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. |
| Exploit 1mo ago | 9.8 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. |
| Exploit 1mo ago | 9.8 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. |
| Exploit 1mo ago | 9.8 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
| 1mo ago | 9.8 | An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled. |
| 1mo ago | 9.8 | An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases. |
| Exploit 1mo ago | 9.8 | XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. |
| 1mo ago | 9.8 | cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter. |
| 1mo ago | 10 | The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve malicious content from a third-party attacker-controlled system. Second, arguably more severe, is the potential for an attacker to circumvent firewall controls, by proxying traffic, unauthenticated, into the internal network from the internet. |
| 1mo ago | 9.8 | An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption. |
| 1mo ago | 9.8 | An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing. |
| 1mo ago | 9.8 | An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling. |
| 1mo ago | 9.8 | An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled. |
| Exploit 1mo ago | 9.8 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. |
| Exploit 1mo ago | 9.8 | XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. |
| Exploit 1mo ago | 9.8 | FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php. |
| Exploit 1mo ago | 9.8 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. |
| Exploit 1mo ago | 9.8 | DianoxDragon Hawn before 2019-07-10 allows SQL injection. |
| 1mo ago | 9.1 | IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702. |
| Exploit 1mo ago | 9.8 | Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. |
| Exploit 1mo ago | 9.8 | Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. |
| Exploit 1mo ago | 9.8 | Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. |
| Exploit 1mo ago | 9.8 | The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php. |
| Exploit 1mo ago | 9.8 | BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. |
| Exploit 1mo ago | 9.8 | HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. |
| Exploit 1mo ago | 9.8 | idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. |
| Exploit 1mo ago | 9.8 | OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. |
| Exploit 1mo ago | 9.8 | The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. |