CVE-2024-29889 | HIGH | 7.1 | 0.6296 | 50.44 | No | No | 2024-05-07 | 2024-08-02 | euvd | GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability i…GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15. |
CVE-2022-31626 | HIGH | 7.5 | 0.5838 | 50.43 | No | Yes | 2022-06-16 | 2024-09-17 | euvd, github | In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third pa…In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability. |
CVE-2023-6702 | HIGH | 8.8 | 0.4351 | 50.43 | No | No | 2023-12-14 | 2025-11-04 | euvd | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted…Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2023-0286 | HIGH | 7.4 | 0.59501 | 50.43 | No | No | 2023-02-08 | 2025-11-04 | euvd | There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName. X.400 addresses were parsed as an …There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but
the public structure definition for GENERAL_NAME incorrectly specified the type
of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by
the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an
ASN1_STRING.
When CRL checking is enabled (i.e. the application sets the
X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass
arbitrary pointers to a memcmp call, enabling them to read memory contents or
enact a denial of service. In most cases, the attack requires the attacker to
provide both the certificate chain and CRL, neither of which need to have a
valid signature. If the attacker only controls one of these inputs, the other
input must already contain an X.400 address as a CRL distribution point, which
is uncommon. As such, this vulnerability is most likely to only affect
applications which have implemented their own functionality for retrieving CRLs
over a network. |
CVE-2021-21351 | MEDIUM | 5.4 | 0.82136 | 50.35 | No | No | 2021-03-22 | 2024-08-03 | euvd | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a…XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16. |
CVE-2021-43829 | HIGH | 7.4 | 0.59246 | 50.34 | No | No | 2021-12-14 | 2024-08-04 | euvd | PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly han…PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue. |
CVE-2026-20896 | CRITICAL | 9.8 | 0.31809 | 50.33 | No | Yes | 2026-07-03 | 2026-07-07 | euvd, github, packetstorm | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate…Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. |
CVE-2022-0557 | HIGH | 8.1 | 0.51193 | 50.32 | No | No | 2022-02-11 | 2024-08-02 | euvd | OS Command Injection in Packagist microweber/microweber prior to 1.2.11.OS Command Injection in Packagist microweber/microweber prior to 1.2.11. |
CVE-2021-40728 | HIGH | 7.8 | 0.54627 | 50.32 | No | No | 2021-10-15 | 2025-04-23 | euvd | Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and ea…Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free vulnerability in the processing of the GetURL function on a global object window that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
CVE-2022-35870 | HIGH | 8.8 | 0.43103 | 50.29 | No | No | 2022-07-25 | 2024-08-03 | euvd | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202…This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within com.inductiveautomation.metro.impl. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17265. |
CVE-2021-21892 | CRITICAL | 9.9 | 0.30436 | 50.25 | No | No | 2021-12-22 | 2024-08-03 | euvd | A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QE…A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
CVE-2004-1464 | MEDIUM | 5.9 | 0.0471 | 50.25 | Yes | No | 2005-02-13 | 2025-10-22 | cisa.gov, euvd | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a craf…Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port. |
CVE-2021-34478 | HIGH | 7.8 | 0.54383 | 50.23 | No | No | 2021-08-12 | 2026-08-10 | euvd | Microsoft Office Remote Code Execution VulnerabilityMicrosoft Office Remote Code Execution Vulnerability |
CVE-2023-28770 | HIGH | 7.5 | 0.57778 | 50.22 | No | No | 2023-04-27 | 2025-01-31 | euvd | The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to…The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file. |
CVE-2023-5044 | HIGH | 7.6 | 0.56568 | 50.2 | No | No | 2023-10-25 | 2025-06-12 | euvd | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. |
CVE-2024-52301 | HIGH | 8.7 | 0.44004 | 50.2 | No | No | 2024-11-12 | 2024-12-21 | euvd | Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special craft…Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs. |
CVE-2025-6440 | CRITICAL | 9.8 | 0.31424 | 50.2 | No | No | 2025-10-24 | 2026-04-08 | euvd | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to…The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. |
CVE-2021-25369 | MEDIUM | 6.2 | 0.01121 | 50.19 | Yes | No | 2021-03-26 | 2025-10-21 | cisa.gov, euvd | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. |
CVE-2022-43568 | HIGH | 8.8 | 0.42801 | 50.18 | No | No | 2022-11-04 | 2025-05-01 | euvd | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notat…In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio. |
CVE-2022-3562 | MEDIUM | 4.3 | 0.94216 | 50.18 | No | No | 2022-11-20 | 2025-04-28 | euvd | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
CVE-2021-36952 | HIGH | 7.8 | 0.54171 | 50.16 | No | No | 2021-09-15 | 2026-08-10 | euvd | Visual Studio Remote Code Execution VulnerabilityVisual Studio Remote Code Execution Vulnerability |
CVE-2009-2512 | CRITICAL | 9.8 | 0.31215 | 50.13 | No | No | 2009-11-11 | 2025-01-21 | euvd | The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the head…The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services on Devices API Memory Corruption Vulnerability." |
CVE-2024-10124 | CRITICAL | 9.8 | 0.31217 | 50.13 | No | No | 2024-12-12 | 2026-04-08 | euvd | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installat…The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. This vulnerability was partially patched in version 1.1.1. |
CVE-2025-10573 | CRITICAL | 9.6 | 0.33499 | 50.12 | No | No | 2025-12-09 | 2026-02-26 | cnvd, euvd | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript…Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required. |
CVE-2020-16875 | HIGH | 8.4 | 0.47145 | 50.1 | No | No | 2020-09-11 | 2024-08-04 | euvd | <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attac…<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p>
<p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p> |
CVE-2023-25762 | MEDIUM | 5.4 | 0.814 | 50.09 | No | No | 2023-02-15 | 2025-03-19 | euvd | Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Gener…Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names. |
CVE-2023-51126 | CRITICAL | 9.8 | 0.31097 | 50.08 | No | No | 2024-01-10 | 2025-10-17 | euvd | Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value param…Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16. |
CVE-2025-59689 | MEDIUM | 6.1 | 0.01913 | 50.07 | Yes | No | 2025-09-19 | 2026-02-26 | cisa.gov, euvd | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been release…Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7. |
CVE-2017-2894 | CRITICAL | 9.8 | 0.31045 | 50.07 | No | No | 2017-11-07 | 2024-09-17 | euvd | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially craf…An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability. |
CVE-2025-6970 | HIGH | 7.5 | 0.57307 | 50.06 | No | No | 2025-07-09 | 2026-04-08 | euvd | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’…The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
CVE-2021-21477 | CRITICAL | 9.9 | 0.29847 | 50.05 | No | No | 2021-02-09 | 2024-08-03 | euvd | SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticat…SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application. |
CVE-2023-25279 | CRITICAL | 9.8 | 0.30987 | 50.05 | No | No | 2023-03-13 | 2025-03-03 | euvd | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload. |
CVE-2024-38217 | MEDIUM | 5.4 | 0.09835 | 50.04 | Yes | No | 2024-09-10 | 2026-08-10 | cisa.gov, euvd | Windows Mark of the Web Security Feature Bypass VulnerabilityWindows Mark of the Web Security Feature Bypass Vulnerability |
CVE-2021-28164 | MEDIUM | 5.3 | 0.82371 | 50.03 | No | No | 2021-04-01 | 2024-08-03 | euvd | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segm…In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application. |
CVE-2022-1181 | HIGH | 8.0 | 0.51472 | 50.02 | No | No | 2022-03-30 | 2024-08-02 | euvd | Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2. |
CVE-2025-48700 | MEDIUM | 6.1 | 0.01761 | 50.02 | Yes | No | 2025-06-23 | 2026-04-21 | cisa.gov, euvd | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zi…An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction. |
CVE-2022-45701 | HIGH | 8.8 | 0.42326 | 50.01 | No | No | 2023-02-17 | 2026-07-09 | euvd | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. |
CVE-2020-6092 | HIGH | 8.8 | 0.42268 | 49.99 | No | No | 2020-05-18 | 2024-08-04 | euvd | An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can …An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order to trigger this vulnerability, victim must open a malicious file. |
CVE-2021-1906 | MEDIUM | 6.2 | 0.0052 | 49.98 | Yes | No | 2021-05-07 | 2025-10-21 | cisa.gov, euvd | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Comput…Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
CVE-2023-50290 | MEDIUM | 6.5 | 0.68446 | 49.96 | No | No | 2024-01-15 | 2025-05-09 | euvd | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.
The Solr Metrics API publishes all unprotected envi…Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.
The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide, however, the default list is designed to work for known secret Java system properties. Environment variables cannot be strictly defined in Solr, like Java system properties can be, and may be set for the entire host, unlike Java system properties which are set per-Java-proccess.
The Solr Metrics API is protected by the "metrics-read" permission.
Therefore, Solr Clouds with Authorization setup will only be vulnerable via users with the "metrics-read" permission.
This issue affects Apache Solr: from 9.0.0 before 9.3.0.
Users are recommended to upgrade to version 9.3.0 or later, in which environment variables are not published via the Metrics API. |
CVE-2016-0162 | MEDIUM | 4.3 | 0.22088 | 49.93 | Yes | No | 2016-04-12 | 2025-10-21 | cisa.gov, euvd | Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Inter…Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability." |
CVE-2023-32029 | HIGH | 7.8 | 0.53513 | 49.93 | No | No | 2023-06-13 | 2025-11-04 | euvd | Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Excel Remote Code Execution Vulnerability |
CVE-2023-21237 | MEDIUM | 6.2 | 0.00264 | 49.89 | Yes | No | 2023-06-28 | 2025-10-21 | cisa.gov, euvd | In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or…In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912 |
CVE-2020-1074 | HIGH | 7.8 | 0.53399 | 49.89 | No | No | 2020-09-11 | 2024-08-04 | euvd | <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who s…<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p>
<p>An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.</p>
<p>The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.</p> |
CVE-2023-22232 | MEDIUM | 5.3 | 0.81875 | 49.86 | No | No | 2023-02-17 | 2025-03-05 | euvd | Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result…Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction. |
CVE-2022-2586 | MEDIUM | 5.3 | 0.10458 | 49.86 | Yes | Yes | 2024-01-08 | 2025-10-21 | cisa.gov, euvd, packetstorm | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that …It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. |
CVE-2026-22557 | CRITICAL | 10.0 | 0.28134 | 49.85 | No | Yes | 2026-03-19 | 2026-03-19 | euvd, packetstorm | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access f…A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account. |
CVE-2020-14825 | CRITICAL | 9.8 | 0.30401 | 49.84 | No | No | 2020-10-21 | 2024-09-26 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2022-27498 | CRITICAL | 9.1 | 0.38338 | 49.82 | No | No | 2022-12-19 | 2025-04-15 | euvd | A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10…A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability. |
CVE-2021-34501 | HIGH | 7.8 | 0.53178 | 49.81 | No | No | 2021-07-14 | 2026-08-10 | euvd | Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Excel Remote Code Execution Vulnerability |