CVE-2020-10923 | MEDIUM | 6.5 | 0.84676 | 55.64 | No | No | 2020-07-28 | 2024-08-04 | euvd | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 r…This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000. A crafted UPnP message can be used to bypass authentication. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-9642. |
CVE-2025-64095 | CRITICAL | 10.0 | 0.44656 | 55.63 | No | No | 2025-10-28 | 2025-10-29 | euvd | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default H…DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1. |
CVE-2024-30568 | CRITICAL | 9.8 | 0.46918 | 55.62 | No | No | 2024-04-03 | 2024-08-21 | euvd | Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. |
CVE-2020-14645 | CRITICAL | 9.8 | 0.46855 | 55.6 | No | No | 2020-07-15 | 2024-09-27 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2023-3643 | HIGH | 7.3 | 0.75363 | 55.58 | No | No | 2023-07-12 | 2024-08-02 | euvd | A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/s…A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability. |
CVE-2022-27926 | MEDIUM | 6.1 | 0.17634 | 55.57 | Yes | No | 2023-04-03 | 2023-04-03 | cisa.gov, euvd | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters with…Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing. |
CVE-2022-41076 | HIGH | 8.5 | 0.61605 | 55.56 | No | No | 2022-12-13 | 2025-07-22 | euvd | PowerShell Remote Code Execution VulnerabilityPowerShell Remote Code Execution Vulnerability |
CVE-2020-36239 | CRITICAL | 9.8 | 0.46689 | 55.54 | No | No | 2021-07-29 | 2024-10-17 | euvd | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b…Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated. |
CVE-2021-39836 | HIGH | 7.8 | 0.69538 | 55.54 | No | No | 2021-09-29 | 2024-09-16 | euvd | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
CVE-2018-13374 | MEDIUM | 4.3 | 0.38088 | 55.53 | Yes | No | 2022-09-08 | 2022-09-08 | cisa.gov, euvd | Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credent…Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server. |
CVE-2024-21287 | HIGH | 7.5 | 0.01496 | 55.52 | Yes | No | 2024-11-21 | 2024-11-21 | cisa.gov, euvd | Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the …Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure. |
CVE-2023-48241 | HIGH | 7.5 | 0.7282 | 55.49 | No | No | 2023-11-20 | 2024-08-02 | euvd | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr…XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki exposes the content of all documents of all wikis to anybody who has access to it, by default it is public. This exposes all information stored in the wiki (but not some protected information like password hashes). While there is a right check normally, the right check can be circumvented by explicitly requesting fields from Solr that don't include the data for the right check. This has been fixed in XWiki 15.6RC1, 15.5.1 and 14.10.15 by not listing documents whose rights cannot be checked. No known workarounds are available. |
CVE-2025-49533 | CRITICAL | 9.8 | 0.46529 | 55.49 | No | No | 2025-07-08 | 2026-02-26 | euvd | Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lea…Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged. |
CVE-2023-34133 | HIGH | 7.5 | 0.72767 | 55.47 | No | No | 2023-07-13 | 2025-04-23 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an …Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. |
CVE-2024-12971 | HIGH | 8.6 | 0.60194 | 55.47 | No | No | 2025-03-17 | 2025-03-17 | euvd | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from …Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6 |
CVE-2023-41179 | HIGH | 7.2 | 0.04739 | 55.46 | Yes | No | 2023-09-21 | 2023-09-21 | cisa.gov, euvd | Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that co…Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. |
CVE-2022-42424 | HIGH | 7.2 | 0.76134 | 55.45 | No | No | 2023-03-29 | 2025-02-14 | euvd | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to explo…This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18556. |
CVE-2022-42425 | HIGH | 7.2 | 0.76134 | 55.45 | No | No | 2023-03-29 | 2025-02-14 | euvd | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to explo…This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18555. |
CVE-2022-47939 | CRITICAL | 9.8 | 0.46428 | 55.45 | No | No | 2022-12-23 | 2025-04-14 | euvd | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for S…An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT. |
CVE-2022-42427 | HIGH | 7.2 | 0.76134 | 55.45 | No | No | 2023-03-29 | 2025-02-14 | euvd | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to explo…This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18541. |
CVE-2023-0126 | HIGH | 7.5 | 0.72699 | 55.44 | No | No | 2023-01-19 | 2025-04-03 | euvd | Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbit…Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory. |
CVE-2023-34124 | CRITICAL | 9.8 | 0.46366 | 55.43 | No | No | 2023-07-13 | 2025-04-08 | euvd | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue…The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. |
CVE-2023-22374 | HIGH | 7.5 | 0.72646 | 55.43 | No | No | 2023-02-01 | 2025-03-26 | euvd | A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, poten…A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
CVE-2022-34718 | CRITICAL | 9.8 | 0.46365 | 55.43 | No | No | 2022-09-13 | 2025-03-11 | euvd | Windows TCP/IP Remote Code Execution VulnerabilityWindows TCP/IP Remote Code Execution Vulnerability |
CVE-2024-20017 | CRITICAL | 9.8 | 0.46331 | 55.42 | No | No | 2024-03-04 | 2024-09-25 | euvd | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132. |
CVE-2024-44849 | CRITICAL | 9.8 | 0.46287 | 55.4 | No | No | 2024-09-09 | 2025-06-12 | euvd | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. |
CVE-2023-2982 | CRITICAL | 9.8 | 0.46242 | 55.38 | No | No | 2023-06-29 | 2026-04-08 | euvd | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in …The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5. |
CVE-2023-30145 | CRITICAL | 9.8 | 0.46136 | 55.35 | No | No | 2023-05-26 | 2025-01-16 | euvd | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. |
CVE-2024-7591 | CRITICAL | 10.0 | 0.43844 | 55.35 | No | No | 2024-09-05 | 2025-02-18 | euvd | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects:
* LoadMaster: 7.2.40.0 and a…Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects:
* LoadMaster: 7.2.40.0 and above
* ECS: All versions
* Multi-Tenancy: 7.1.35.4 and above |
CVE-2023-4346 | HIGH | 7.5 | 0.00907 | 55.32 | Yes | No | 2026-07-15 | 2026-07-15 | cisa.gov, euvd | KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that c…KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. |
CVE-2024-37014 | HIGH | 8.8 | 0.57485 | 55.32 | No | No | 2024-06-10 | 2024-08-02 | euvd | Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and p…Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script. |
CVE-2024-3721 | MEDIUM | 6.3 | 0.86008 | 55.3 | No | No | 2024-04-13 | 2024-08-01 | euvd | A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing…A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability. |
CVE-2025-27038 | HIGH | 7.5 | 0.00831 | 55.29 | Yes | No | 2025-06-03 | 2025-06-03 | cisa.gov, euvd | Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics …Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. |
CVE-2024-24401 | CRITICAL | 9.8 | 0.45884 | 55.26 | No | No | 2024-02-26 | 2024-08-29 | euvd | SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitorin…SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component. |
CVE-2024-39363 | CRITICAL | 9.6 | 0.48086 | 55.23 | No | No | 2025-01-14 | 2025-01-14 | euvd | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505…A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. |
CVE-2024-38106 | HIGH | 7.0 | 0.06337 | 55.22 | Yes | No | 2024-08-13 | 2024-08-13 | cisa.gov, euvd | Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTE…Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. |
CVE-2023-51573 | CRITICAL | 9.8 | 0.45744 | 55.21 | No | No | 2024-04-01 | 2024-08-02 | euvd | Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allow…Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the updateManagerPassword function. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21203. |
CVE-2026-20122 | MEDIUM | 5.4 | 0.24585 | 55.2 | Yes | No | 2026-04-20 | 2026-04-20 | cisa.gov, euvd | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface …Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. |
CVE-2025-29306 | CRITICAL | 9.8 | 0.45675 | 55.19 | No | No | 2025-03-27 | 2025-03-28 | euvd | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. |
CVE-2023-23492 | HIGH | 8.8 | 0.57123 | 55.19 | No | No | 2023-01-20 | 2025-04-03 | euvd | The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' param…The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action. |
CVE-2022-41328 | MEDIUM | 6.5 | 0.11912 | 55.17 | Yes | No | 2023-03-14 | 2023-03-14 | cisa.gov, euvd | Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI …Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. |
CVE-2025-2749 | HIGH | 7.2 | 0.03854 | 55.15 | Yes | No | 2026-04-20 | 2026-04-20 | cisa.gov, cnvd, euvd | Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary d…Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. |
CVE-2019-11542 | HIGH | 8.0 | 0.6612 | 55.14 | No | No | 2019-04-26 | 2024-08-04 | euvd | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an…In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow. |
CVE-2024-38226 | HIGH | 7.3 | 0.02667 | 55.13 | Yes | No | 2024-09-10 | 2024-09-10 | cisa.gov, euvd | Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block…Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. |
CVE-2023-41887 | CRITICAL | 9.8 | 0.45473 | 55.12 | No | No | 2023-09-15 | 2024-09-25 | euvd | OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability a…OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue. |
CVE-2022-20821 | MEDIUM | 6.5 | 0.1176 | 55.12 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open p…Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container. |
CVE-2022-33318 | CRITICAL | 9.8 | 0.4548 | 55.12 | No | No | 2022-07-20 | 2026-01-09 | euvd | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi…Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric GENESIS32 versions 9.7 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows a remote unauthenticated attacker to execute an arbitrary malicious code by sending specially crafted packets to the GENESIS64, ICONICS Suite, GENESIS32, or MC Works64 server. |
CVE-2022-21500 | HIGH | 7.5 | 0.71703 | 55.1 | No | No | 2022-05-19 | 2024-09-24 | euvd | Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vul…Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. <br> <br>Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
CVE-2025-62215 | HIGH | 7.0 | 0.05985 | 55.09 | Yes | No | 2025-11-12 | 2025-11-12 | cisa.gov, euvd | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileg…Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access. |
CVE-2013-3632 | HIGH | 8.8 | 0.56838 | 55.09 | No | No | 2014-09-29 | 2024-08-06 | euvd | The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrar…The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter. |