CVE-2024-38189 | HIGH | 8.8 | 0.08194 | 63.07 | Yes | No | 2024-08-13 | 2025-10-21 | cisa.gov, euvd | Microsoft Project Remote Code Execution VulnerabilityMicrosoft Project Remote Code Execution Vulnerability |
CVE-2023-0315 | HIGH | 7.2 | 0.97653 | 62.98 | No | No | 2023-01-16 | 2025-04-07 | euvd | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. |
CVE-2023-30253 | HIGH | 8.8 | 0.79335 | 62.97 | No | No | 2023-05-29 | 2025-01-14 | euvd | Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in inject…Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. |
CVE-2025-53521 | CRITICAL | 9.3 | 0.02213 | 62.97 | Yes | No | 2025-10-15 | 2026-03-31 | cisa.gov, euvd | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
No…When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
CVE-2023-5074 | CRITICAL | 9.8 | 0.67914 | 62.97 | No | No | 2023-09-20 | 2024-09-24 | euvd | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.2…Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 |
CVE-2026-9198 | HIGH | 8.0 | 0.17053 | 62.97 | Yes | Yes | 2026-08-07 | 2026-08-07 | cisa.gov, cnvd, euvd, github, nvd, packetstorm | IBM Langflow OSS is an open source low-code visual AI workflow construction tool from IBM in the United States. It allows developers to quic…IBM Langflow OSS is an open source low-code visual AI workflow construction tool from IBM in the United States. It allows developers to quickly build, deploy and iterate AI agents and RAG applications by dragging and dropping components. It also supports in-depth customization using Python to integrate enterprise systems. IBM Langflow OSS has a code injection vulnerability. This vulnerability is caused by flaws in the authentication and code execution modules. An attacker can use this vulnerability to achieve remote code execution by concatenating the /api/v1/auto_login and /api/v1/validate/code interfaces. |
CVE-2022-3723 | HIGH | 8.8 | 0.07857 | 62.95 | Yes | No | 2022-11-01 | 2025-10-21 | cisa.gov, euvd | Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted …Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2021-4102 | HIGH | 8.8 | 0.07836 | 62.94 | Yes | No | 2022-02-11 | 2025-10-21 | cisa.gov, euvd | Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted …Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2019-1215 | HIGH | 7.8 | 0.19254 | 62.94 | Yes | No | 2019-09-11 | 2025-10-21 | cisa.gov, euvd | An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Pr…An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303. |
CVE-2020-5398 | HIGH | 8.0 | 0.88402 | 62.94 | No | No | 2020-01-16 | 2024-09-16 | euvd | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vu…In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. |
CVE-2021-34448 | MEDIUM | 6.8 | 0.3067 | 62.93 | Yes | No | 2021-07-16 | 2025-10-21 | cisa.gov, euvd | Scripting Engine Memory Corruption VulnerabilityScripting Engine Memory Corruption Vulnerability |
CVE-2019-1322 | HIGH | 7.8 | 0.19205 | 62.92 | Yes | No | 2019-10-10 | 2025-10-21 | cisa.gov, euvd | An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of …An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340. |
CVE-2021-30952 | HIGH | 8.8 | 0.07617 | 62.87 | Yes | No | 2021-08-24 | 2026-03-06 | cisa.gov, euvd | An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15…An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution. |
CVE-2026-48027 | CRITICAL | 9.3 | 0.0185 | 62.85 | Yes | No | 2026-05-27 | 2026-08-04 | cisa.gov, euvd | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC a…Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version. |
CVE-2015-5317 | HIGH | 7.5 | 0.22429 | 62.85 | Yes | No | 2015-11-25 | 2025-10-21 | cisa.gov, euvd | The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name in…The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request. |
CVE-2023-2732 | CRITICAL | 9.8 | 0.67511 | 62.83 | No | No | 2023-05-25 | 2026-04-08 | euvd | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insuffici…The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. |
CVE-2024-7262 | CRITICAL | 9.3 | 0.01773 | 62.82 | Yes | No | 2024-08-15 | 2025-10-21 | cisa.gov, euvd | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on W…Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library.
The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document |
CVE-2023-32707 | HIGH | 8.8 | 0.78877 | 62.81 | No | No | 2023-06-01 | 2025-03-11 | euvd | In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged use…In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests. |
CVE-2023-40497 | CRITICAL | 9.8 | 0.67414 | 62.79 | No | No | 2024-05-03 | 2024-09-18 | euvd | LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the saveXml command implemented in the makeDetailContent method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
. Was ZDI-CAN-19924. |
CVE-2021-30554 | HIGH | 8.8 | 0.07367 | 62.78 | Yes | No | 2021-07-02 | 2025-10-21 | cisa.gov, euvd | Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a craft…Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2023-7024 | HIGH | 8.8 | 0.07356 | 62.77 | Yes | No | 2023-12-21 | 2025-10-21 | cisa.gov, euvd | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via…Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2015-0071 | MEDIUM | 6.5 | 0.33581 | 62.75 | Yes | No | 2015-02-11 | 2025-10-22 | cisa.gov, euvd | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Intern…Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability." |
CVE-2025-47813 | MEDIUM | 4.3 | 0.58727 | 62.75 | Yes | No | 2025-07-10 | 2026-03-17 | cisa.gov, euvd | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI…loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. |
CVE-2024-3552 | CRITICAL | 9.8 | 0.67288 | 62.75 | No | No | 2024-06-13 | 2025-03-25 | euvd | The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX…The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based. |
CVE-2025-22224 | CRITICAL | 9.3 | 0.01561 | 62.75 | Yes | No | 2025-03-04 | 2026-02-26 | cisa.gov, euvd | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious ac…VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. |
CVE-2023-28302 | HIGH | 7.5 | 0.93559 | 62.75 | No | No | 2023-04-11 | 2025-02-28 | euvd | Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability |
CVE-2024-27954 | CRITICAL | 9.3 | 0.72953 | 62.73 | No | No | 2024-05-17 | 2026-04-28 | euvd | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal…Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0. |
CVE-2017-6744 | HIGH | 8.8 | 0.07158 | 62.71 | Yes | No | 2017-07-17 | 2025-10-21 | cisa.gov, euvd | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow …The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.
The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload.
Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable.
There are workarounds that address these vulnerabilities. |
CVE-2026-8398 | CRITICAL | 9.3 | 0.01456 | 62.71 | Yes | No | 2026-05-15 | 2026-05-28 | cisa.gov, euvd | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434)…A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection. |
CVE-2020-8617 | HIGH | 7.5 | 0.93422 | 62.7 | No | No | 2020-05-19 | 2024-09-16 | euvd | Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or …Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results. |
CVE-2022-43672 | CRITICAL | 9.8 | 0.67078 | 62.68 | No | No | 2022-11-12 | 2025-05-01 | euvd | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a diffe…Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. |
CVE-2015-5123 | HIGH | 7.8 | 0.18493 | 62.67 | Yes | No | 2015-07-14 | 2025-11-17 | cisa.gov, euvd | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.30…Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015. |
CVE-2023-38545 | HIGH | 8.8 | 0.78483 | 62.67 | No | No | 2023-10-18 | 2026-07-14 | euvd | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is asked to pass along the host name to the SOCK…This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.
If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means "let the host resolve the name" could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.
The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with. |
CVE-2022-22718 | HIGH | 7.8 | 0.18464 | 62.66 | Yes | No | 2022-02-09 | 2025-10-21 | cisa.gov, euvd | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability |
CVE-2023-29516 | CRITICAL | 9.9 | 0.65869 | 62.65 | No | No | 2023-04-18 | 2025-02-05 | euvd | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki…XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping in the "Cancel and return to page" button. This page is installed by default. This vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. There are no known workarounds for this vulnerability. |
CVE-2020-8195 | MEDIUM | 6.5 | 0.33263 | 62.64 | Yes | No | 2020-07-10 | 2025-10-21 | cisa.gov, euvd | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and…Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. |
CVE-2018-8440 | HIGH | 7.8 | 0.18386 | 62.64 | Yes | No | 2018-09-13 | 2025-10-21 | cisa.gov, euvd | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows A…An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. |
CVE-2025-55315 | CRITICAL | 9.9 | 0.65838 | 62.64 | No | No | 2025-10-14 | 2026-02-22 | euvd | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a s…Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. |
CVE-2025-34299 | CRITICAL | 9.3 | 0.72667 | 62.63 | No | No | 2025-11-07 | 2026-05-14 | euvd | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers…Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server. |
CVE-2008-3431 | HIGH | 8.8 | 0.06932 | 62.63 | Yes | No | 2008-08-05 | 2025-10-22 | cisa.gov, euvd | The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTL…The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address. |
CVE-2013-3900 | MEDIUM | 5.5 | 0.44647 | 62.63 | Yes | No | 2013-12-11 | 2025-10-22 | cisa.gov, euvd | Why is Microsoft republishing a CVE from 2013?
We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates…Why is Microsoft republishing a CVE from 2013?
We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013,
Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. This includes all currently supported versions of Windows 10 and Windows 11. The supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. See the Security Updates table for the list of affected software.
Vulnerability Description
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a way as to add malicious code to the file without invalidating the signature. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of this vulnerability requires that a user or application run or install a specially crafted, signed PE file. An attacker could modify an... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900 |
CVE-2023-38204 | CRITICAL | 9.8 | 0.66837 | 62.59 | No | No | 2023-09-14 | 2025-02-27 | euvd | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untruste…Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. |
CVE-2025-59374 | CRITICAL | 9.3 | 0.01128 | 62.59 | Yes | No | 2025-12-17 | 2026-02-26 | cisa.gov, euvd | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced thro…"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue. |
CVE-2024-28741 | HIGH | 8.8 | 0.78158 | 62.56 | No | No | 2024-04-06 | 2024-08-15 | euvd | Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php co…Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component. |
CVE-2023-28434 | HIGH | 8.8 | 0.06681 | 62.54 | Yes | No | 2023-03-22 | 2025-10-21 | cisa.gov, euvd | Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metad…Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`. |
CVE-2010-4345 | HIGH | 7.8 | 0.18105 | 62.54 | Yes | No | 2010-12-14 | 2025-10-22 | cisa.gov, euvd | Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confi…Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive. |
CVE-2021-20039 | HIGH | 8.8 | 0.7811 | 62.54 | No | No | 2021-12-08 | 2025-09-05 | euvd | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenti…Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. |
CVE-2021-2190 | HIGH | 7.5 | 0.92907 | 62.52 | No | No | 2021-04-22 | 2024-09-26 | euvd | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). Supported versions that are affected are…Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Sales Offline. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). |
CVE-2025-2777 | CRITICAL | 9.3 | 0.72268 | 62.49 | No | No | 2025-05-07 | 2026-02-26 | euvd | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing funct…SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives. |
CVE-2022-23305 | CRITICAL | 9.8 | 0.66537 | 62.49 | No | No | 2022-01-18 | 2026-05-27 | euvd | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are convert…By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. |