CVE Scouter

Showing 50 of 374412 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2024-32964CRITICAL9.00.5268354.44NoNo2024-05-102024-08-02euvdLobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, l…Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.
CVE-2025-27920HIGH7.20.0179654.43YesNo2025-05-192025-05-19cisa.gov, euvdSrimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended …Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
CVE-2024-7694HIGH7.20.0180754.43YesNo2026-02-172026-02-17cisa.gov, euvdTeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware do…TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.
CVE-2025-30065CRITICAL10.00.4123154.43NoNo2025-04-012026-02-26euvdSchema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users…Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
CVE-2021-25487HIGH7.30.0063554.42YesNo2023-06-292023-06-29cisa.gov, euvdSamsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a…Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.
CVE-2024-42640CRITICAL9.80.4346454.41NoNo2024-10-112024-10-15euvdangular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerabi…angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-3080CRITICAL9.80.4345654.41NoNo2024-06-142024-08-01euvdCertain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
CVE-2025-49132CRITICAL10.00.4113754.4NoYes2025-06-202025-06-20euvd, packetstormPterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale an…Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.
CVE-2018-5378HIGH7.10.74254.37NoNo2018-02-192024-09-16euvdThe Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute le…The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.
CVE-2019-0703MEDIUM6.50.096454.37YesNo2022-05-232022-05-23cisa.gov, euvdAn information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to informat…An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
CVE-2025-52665CRITICAL10.00.4097254.34NoNo2025-10-302025-10-31euvdA malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, t…A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.
CVE-2025-68615CRITICAL9.80.4326254.34NoNo2025-12-222026-05-01euvdnet-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp s…net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
CVE-2024-26594CRITICAL9.10.5124854.34NoNo2024-02-232026-08-05euvd, nvdIn the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mec…In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.
CVE-2019-11478MEDIUM5.30.9468654.34NoNo2019-06-182024-09-16euvdJonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when han…Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
CVE-2023-38171HIGH7.50.6949454.32NoNo2023-10-102025-04-14euvdMicrosoft QUIC Denial of Service VulnerabilityMicrosoft QUIC Denial of Service Vulnerability
CVE-2026-2043HIGH7.20.7290854.32NoNo2026-02-202026-02-26euvdNagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote att…Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the esensors_websensor_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28249.
CVE-2021-28639HIGH7.80.6605254.32NoNo2021-08-202024-09-16euvdAcrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Us…Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-27292HIGH7.50.6948654.32NoNo2024-02-292024-08-02euvdDocassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access …Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
CVE-2024-30080CRITICAL9.80.4314554.3NoNo2024-06-112026-07-21euvdMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityMicrosoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-2862CRITICAL9.10.5100154.25NoNo2024-03-252024-08-28euvdThis vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
CVE-2022-23307HIGH8.80.5441154.24NoNo2022-01-182026-05-27euvdCVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apa…CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
CVE-2024-45387CRITICAL9.90.4184154.24NoNo2024-12-232024-12-24euvdAn SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "fede…An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
CVE-2021-27272HIGH7.10.7376654.22NoNo2021-03-292024-08-03euvdThis vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System …This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ReportTemplateController class. When parsing the path parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12123.
CVE-2023-49231CRITICAL9.80.4289854.21NoNo2024-03-292024-10-28euvdAn authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administra…An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.
CVE-2025-21391HIGH7.10.0225854.19YesNo2025-02-112025-02-11cisa.gov, euvdMicrosoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow …Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.
CVE-2023-2986CRITICAL9.80.4281454.18NoNo2023-06-082026-04-08euvdThe Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2…The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as users who have abandoned the cart, who are typically customers. Further security hardening was introduced in version 5.15.1 that ensures sites are no longer vulnerable through historical check-out links, and additional hardening was introduced in version 5.15.2 that ensured null key values wouldn't permit the authentication bypass.
CVE-2023-2564CRITICAL10.00.4051654.18NoNo2023-05-072025-01-29euvdOS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
CVE-2022-42233CRITICAL9.80.4270454.15NoNo2022-10-202025-05-08euvdTenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
CVE-2022-4060CRITICAL9.80.4272354.15NoNo2023-01-162025-04-04euvdThe User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any…The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
CVE-2024-25735CRITICAL9.10.5062254.12NoNo2024-03-272025-11-04euvdAn issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /devi…An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.
CVE-2022-2234CRITICAL9.90.4146654.11NoNo2022-08-242025-04-16euvdAn authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
CVE-2023-21768HIGH7.80.6541754.1NoNo2023-01-102025-01-01euvdWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2022-35710CRITICAL9.80.4257754.1NoNo2022-10-142025-04-23euvdAdobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability tha…Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.
CVE-2023-44352MEDIUM6.10.8481154.08NoNo2023-11-172024-10-29euvdAdobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit…Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
CVE-2025-0111HIGH7.10.0192754.07YesNo2025-02-202025-02-20cisa.gov, euvdPalo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated …Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
CVE-2018-4021HIGH7.20.722154.07NoNo2018-12-032024-09-17euvdAn exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS…An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_battery_mode` POST parameter.
CVE-2026-56164MEDIUM5.30.2243954.05YesYes2026-07-142026-08-07cisa.gov, euvd, githubMissing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a net…Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVE-2021-39837HIGH7.80.6524954.04NoNo2021-09-292024-09-16euvdAcrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-36460CRITICAL10.00.401154.04NoNo2023-07-062025-02-13euvdMastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, an…Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.
CVE-2021-39839HIGH7.80.6524954.04NoNo2021-09-292024-09-16euvdAcrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm getItem action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2021-39838HIGH7.80.6524954.04NoNo2021-09-292024-09-16euvdAcrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetCaption action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-21919HIGH7.00.029554.03YesNo2022-04-252022-04-25cisa.gov, euvdMicrosoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-41379MEDIUM5.50.2009954.03YesNo2022-03-032022-03-03cisa.gov, euvdMicrosoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
CVE-2009-2494CRITICAL9.80.4232954.02NoNo2009-08-122025-01-21euvdThe Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 …The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
CVE-2018-4233HIGH8.80.5377254.02NoNo2018-06-082024-08-05euvdAn issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windo…An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
CVE-2025-22226HIGH7.10.0173554.01YesNo2025-03-042025-03-04cisa.gov, euvdVMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploi…VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
CVE-2012-3363CRITICAL9.10.5024853.99NoNo2013-02-132025-01-16euvdZend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re…Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
CVE-2009-1936CRITICAL9.80.4222353.98NoNo2009-06-052025-01-21euvd_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows re…_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.
CVE-2018-13383MEDIUM4.30.3364753.98YesNo2022-01-102022-01-10cisa.gov, euvdA heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
CVE-2023-28662CRITICAL9.80.4218653.97NoNo2023-03-222025-02-25euvdThe Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerabilit…The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.