CVE-2024-47407 | CRITICAL | 10.0 | 0.64168 | 62.46 | No | No | 2024-11-22 | 2024-11-25 | euvd | A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote att…A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands. |
CVE-2025-30397 | HIGH | 7.5 | 0.21318 | 62.46 | Yes | No | 2025-05-13 | 2026-02-26 | cisa.gov, euvd | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code …Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. |
CVE-2025-5419 | HIGH | 8.8 | 0.0645 | 62.46 | Yes | No | 2025-06-02 | 2026-02-26 | cisa.gov, euvd | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption …Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2022-21371 | HIGH | 7.5 | 0.92649 | 62.43 | No | No | 2022-01-19 | 2024-09-24 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affe…Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
CVE-2022-37958 | HIGH | 8.1 | 0.85762 | 62.42 | No | No | 2022-09-13 | 2025-03-11 | euvd | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution VulnerabilitySPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
CVE-2022-3229 | CRITICAL | 9.8 | 0.66354 | 62.42 | No | No | 2023-02-06 | 2025-03-25 | euvd | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthen…Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing. |
CVE-2023-21758 | HIGH | 7.5 | 0.92529 | 62.39 | No | No | 2023-01-10 | 2025-01-01 | euvd | Windows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityWindows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability |
CVE-2022-3786 | HIGH | 7.5 | 0.92488 | 62.37 | No | No | 2022-11-01 | 2026-04-14 | euvd | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after c…A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. |
CVE-2023-40502 | HIGH | 8.2 | 0.84357 | 62.32 | No | No | 2024-05-03 | 2024-09-18 | euvd | LG Simple Editor cropImage Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete a…LG Simple Editor cropImage Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the implementation of the cropImage command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM.
. Was ZDI-CAN-19951. |
CVE-2023-40494 | HIGH | 8.2 | 0.84357 | 62.32 | No | No | 2024-05-03 | 2024-09-18 | euvd | LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delet…LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the deleteFolder method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM.
. Was ZDI-CAN-19921. |
CVE-2023-40492 | HIGH | 8.2 | 0.84357 | 62.32 | No | No | 2024-05-03 | 2024-09-18 | euvd | LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to…LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM.
. Was ZDI-CAN-19919. |
CVE-2023-36035 | HIGH | 8.0 | 0.86588 | 62.31 | No | No | 2023-11-14 | 2025-10-08 | euvd | Microsoft Exchange Server Spoofing VulnerabilityMicrosoft Exchange Server Spoofing Vulnerability |
CVE-2019-8605 | HIGH | 7.8 | 0.17438 | 62.3 | Yes | No | 2019-12-18 | 2025-10-21 | cisa.gov, euvd | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc…A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges. |
CVE-2019-15271 | HIGH | 8.8 | 0.05979 | 62.29 | Yes | No | 2019-11-26 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote…A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges. |
CVE-2020-11022 | MEDIUM | 6.9 | 0.99019 | 62.26 | No | No | 2020-04-29 | 2026-04-13 | euvd | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM man…In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. |
CVE-2023-26475 | CRITICAL | 10.0 | 0.63587 | 62.26 | No | No | 2023-03-02 | 2025-03-05 | euvd | XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a r…XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade. |
CVE-2022-26500 | HIGH | 8.8 | 0.05828 | 62.24 | Yes | No | 2022-03-17 | 2025-10-21 | cisa.gov, euvd | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to inte…Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code. |
CVE-2023-30805 | CRITICAL | 9.8 | 0.65799 | 62.23 | No | No | 2023-10-10 | 2025-11-28 | euvd | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote …The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter. |
CVE-2023-30806 | CRITICAL | 9.8 | 0.65799 | 62.23 | No | No | 2023-10-10 | 2025-11-22 | euvd | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote …The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell meta-characters in the PHPSESSID cookie. |
CVE-2020-8468 | HIGH | 8.8 | 0.05754 | 62.21 | Yes | No | 2020-03-18 | 2025-10-21 | cisa.gov, euvd | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc…Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication. |
CVE-2023-25076 | CRITICAL | 9.8 | 0.65753 | 62.21 | No | No | 2023-03-30 | 2025-03-05 | euvd | A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80d…A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP or TLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability. |
CVE-2023-45288 | HIGH | 7.5 | 0.91969 | 62.19 | No | No | 2024-04-04 | 2025-11-04 | euvd | An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Mai…An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection. |
CVE-2021-20023 | MEDIUM | 4.9 | 0.50234 | 62.18 | Yes | No | 2021-04-20 | 2025-10-21 | cisa.gov, euvd | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on th…SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. |
CVE-2022-22047 | HIGH | 7.8 | 0.17087 | 62.18 | Yes | No | 2022-07-12 | 2025-10-21 | cisa.gov, euvd | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege VulnerabilityWindows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
CVE-2018-0172 | HIGH | 8.6 | 0.07871 | 62.15 | Yes | No | 2018-03-28 | 2026-01-12 | cisa.gov, euvd | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic…A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow condition on the affected device, which will cause the device to reload and result in a DoS condition. Cisco Bug IDs: CSCvg62730. |
CVE-2021-33544 | HIGH | 7.2 | 0.953 | 62.15 | No | No | 2021-09-13 | 2024-09-16 | euvd | Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to …Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code. |
CVE-2018-0155 | HIGH | 8.6 | 0.07793 | 62.13 | Yes | No | 2018-03-28 | 2026-01-12 | cisa.gov, euvd | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Cata…A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system. This vulnerability affects Catalyst 4500 Supervisor Engine 6-E (K5), Catalyst 4500 Supervisor Engine 6L-E (K10), Catalyst 4500 Supervisor Engine 7-E (K10), Catalyst 4500 Supervisor Engine 7L-E (K10), Catalyst 4500E Supervisor Engine 8-E (K10), Catalyst 4500E Supervisor Engine 8L-E (K10), Catalyst 4500E Supervisor Engine 9-E (K10), Catalyst 4500-X Series Switches (K10), Catalyst 4900M Switch (K5), Catalyst 4948E Ethernet Switch (K5). Cisco Bug IDs: CSCvc40729. |
CVE-2023-29017 | CRITICAL | 10.0 | 0.63186 | 62.12 | No | No | 2023-04-06 | 2025-02-10 | euvd | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handlin…vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds. |
CVE-2025-10585 | HIGH | 8.8 | 0.0543 | 62.1 | Yes | No | 2025-09-24 | 2026-07-14 | cisa.gov, euvd | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted…Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2021-28664 | HIGH | 8.8 | 0.05407 | 62.09 | Yes | No | 2021-05-10 | 2025-10-21 | cisa.gov, euvd | The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achie…The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0. |
CVE-2023-35166 | CRITICAL | 10.0 | 0.6312 | 62.09 | No | No | 2023-06-20 | 2024-12-06 | euvd | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki c…XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5. |
CVE-2023-7101 | HIGH | 7.8 | 0.16832 | 62.09 | Yes | No | 2023-12-24 | 2025-10-21 | cisa.gov, euvd | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary co…Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. |
CVE-2023-44412 | HIGH | 8.2 | 0.83681 | 62.09 | No | No | 2024-05-03 | 2024-09-18 | euvd | D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to…D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the addDv7Probe function. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-19571. |
CVE-2021-27876 | HIGH | 8.1 | 0.13411 | 62.09 | Yes | No | 2021-03-01 | 2025-10-21 | cisa.gov, euvd | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authenticati…An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges. |
CVE-2018-0173 | HIGH | 8.6 | 0.07658 | 62.08 | Yes | No | 2018-03-28 | 2026-01-12 | cisa.gov, euvd | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Versio…A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754. |
CVE-2018-0174 | HIGH | 8.6 | 0.07658 | 62.08 | Yes | No | 2018-03-28 | 2026-01-12 | cisa.gov, euvd | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic…A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuh91645. |
CVE-2024-35286 | CRITICAL | 9.8 | 0.65367 | 62.08 | No | No | 2024-10-21 | 2024-12-10 | euvd | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection …A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations. |
CVE-2023-51409 | CRITICAL | 10.0 | 0.63077 | 62.08 | No | No | 2024-04-12 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT…Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98. |
CVE-2020-36708 | CRITICAL | 9.8 | 0.65342 | 62.07 | No | No | 2023-06-07 | 2026-04-08 | euvd | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1,…The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution. |
CVE-2024-4761 | HIGH | 8.3 | 0.11007 | 62.05 | Yes | No | 2024-05-14 | 2025-12-20 | cisa.gov, euvd | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a …Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) |
CVE-2023-2034 | CRITICAL | 9.1 | 0.73247 | 62.04 | No | No | 2023-04-14 | 2025-02-06 | euvd | Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14. |
CVE-2023-36036 | HIGH | 7.8 | 0.1667 | 62.03 | Yes | No | 2023-11-14 | 2025-10-21 | cisa.gov, euvd | Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
CVE-2024-54676 | CRITICAL | 9.8 | 0.65176 | 62.01 | No | No | 2025-01-08 | 2025-01-08 | euvd | Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering inst…Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation. |
CVE-2024-8522 | CRITICAL | 10.0 | 0.62882 | 62.01 | No | No | 2024-09-12 | 2026-04-08 | euvd | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/…The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
CVE-2025-62168 | CRITICAL | 10.0 | 0.62871 | 62.0 | No | No | 2025-10-17 | 2026-02-26 | euvd | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling …Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Squid to be configured with HTTP authentication. The vulnerability is fixed in version 7.2. As a workaround, disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off. |
CVE-2026-20133 | MEDIUM | 6.5 | 0.31353 | 61.97 | Yes | No | 2026-02-25 | 2026-04-22 | cisa.gov, euvd | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affect…A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system. |
CVE-2026-5281 | HIGH | 8.8 | 0.05036 | 61.96 | Yes | No | 2026-04-01 | 2026-04-02 | cisa.gov, cnvd, euvd, nvd | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execut…Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
CVE-2024-26256 | HIGH | 7.8 | 0.87896 | 61.96 | No | Yes | 2024-04-09 | 2025-05-03 | euvd, github | Libarchive Remote Code Execution VulnerabilityLibarchive Remote Code Execution Vulnerability |
CVE-2024-27316 | HIGH | 7.5 | 0.91327 | 61.96 | No | No | 2024-04-04 | 2025-11-04 | euvd | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a …HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. |
CVE-2023-29325 | HIGH | 8.1 | 0.84386 | 61.94 | No | No | 2023-05-09 | 2025-07-10 | euvd | Windows OLE Remote Code Execution VulnerabilityWindows OLE Remote Code Execution Vulnerability |