CVE-2007-4559 | CRITICAL | 9.8 | 0.27095 | 48.68 | No | No | 2007-08-28 | 2025-01-17 | euvd | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot…Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267. |
CVE-2023-48023 | CRITICAL | 9.1 | 0.35052 | 48.67 | No | No | 2023-11-28 | 2024-10-10 | euvd | Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in…Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment |
CVE-2021-28169 | MEDIUM | 5.3 | 0.7848 | 48.67 | No | No | 2021-06-09 | 2024-08-03 | euvd | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to a…For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application. |
CVE-2025-34392 | CRITICAL | 10.0 | 0.24721 | 48.65 | No | No | 2025-12-10 | 2026-05-14 | euvd | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-…Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload. |
CVE-2018-3949 | HIGH | 7.5 | 0.53297 | 48.65 | No | No | 2018-12-01 | 2024-09-17 | euvd | An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted U…An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive system files. An attacker can send either an unauthenticated or an authenticated web request to trigger this vulnerability. |
CVE-2025-2563 | HIGH | 8.1 | 0.46384 | 48.63 | No | No | 2025-04-14 | 2025-08-27 | euvd | The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon…The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges |
CVE-2024-37843 | HIGH | 7.5 | 0.53242 | 48.63 | No | No | 2024-06-25 | 2024-08-02 | euvd | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. |
CVE-2007-5775 | CRITICAL | 9.8 | 0.26909 | 48.62 | No | No | 2007-11-01 | 2025-04-03 | euvd | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as o…Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes. |
CVE-2019-5436 | HIGH | 7.8 | 0.49739 | 48.61 | No | No | 2019-05-28 | 2026-04-15 | euvd | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
CVE-2014-3566 | LOW | 3.4 | 0.99999 | 48.6 | No | No | 2014-10-15 | 2026-05-28 | euvd | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man…The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. |
CVE-2023-41991 | MEDIUM | 5.5 | 0.04547 | 48.59 | Yes | No | 2023-09-21 | 2025-11-04 | cisa.gov, euvd | A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be ab…A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. |
CVE-2024-1600 | CRITICAL | 9.3 | 0.32506 | 48.58 | No | No | 2024-04-10 | 2024-08-01 | euvd | A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. …A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (`../../`) followed by the desired system file path, URL encoded. Successful exploitation allows the attacker to read any file on the filesystem accessible by the web server. This issue arises due to improper control of filename for include/require statement in the application. |
CVE-2024-27172 | CRITICAL | 9.8 | 0.26811 | 48.58 | No | No | 2024-06-14 | 2025-02-13 | euvd | Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL. |
CVE-2013-0090 | HIGH | 8.8 | 0.38223 | 48.58 | No | No | 2013-03-13 | 2025-01-16 | euvd | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web…Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability." |
CVE-2022-38419 | HIGH | 7.5 | 0.53028 | 48.56 | No | No | 2022-10-14 | 2025-04-23 | euvd | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity …Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction. |
CVE-2025-49002 | HIGH | 8.2 | 0.45022 | 48.56 | No | No | 2025-06-03 | 2025-06-04 | euvd | DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for…DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available. |
CVE-2025-53778 | HIGH | 8.8 | 0.38176 | 48.56 | No | No | 2025-08-12 | 2026-02-26 | euvd | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. |
CVE-2024-6386 | CRITICAL | 9.9 | 0.25533 | 48.54 | No | No | 2024-08-21 | 2026-04-08 | euvd | The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Templ…The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. |
CVE-2021-21345 | MEDIUM | 5.8 | 0.72324 | 48.51 | No | No | 2021-03-22 | 2024-08-03 | euvd | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may a…XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16. |
CVE-2024-51977 | MEDIUM | 5.3 | 0.78001 | 48.5 | No | No | 2025-06-25 | 2026-03-30 | euvd | An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP …An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number. |
CVE-2022-22017 | HIGH | 8.8 | 0.37987 | 48.5 | No | No | 2022-05-10 | 2025-01-02 | euvd | Remote Desktop Client Remote Code Execution VulnerabilityRemote Desktop Client Remote Code Execution Vulnerability |
CVE-2024-42010 | HIGH | 7.5 | 0.5281 | 48.48 | No | No | 2024-08-05 | 2024-08-12 | euvd | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren…mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information. |
CVE-2023-21689 | CRITICAL | 9.8 | 0.26504 | 48.48 | No | No | 2023-02-14 | 2025-01-01 | euvd | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
CVE-2024-5315 | CRITICAL | 9.1 | 0.34522 | 48.48 | No | No | 2024-05-24 | 2024-08-01 | euvd | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker…Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters
viewstatut in /dolibarr/commande/list.php. |
CVE-2009-2493 | HIGH | 8.8 | 0.379 | 48.47 | No | No | 2009-07-29 | 2026-05-27 | euvd | The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 200…The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability." |
CVE-2024-5452 | CRITICAL | 9.8 | 0.26488 | 48.47 | No | No | 2024-06-06 | 2025-10-15 | euvd | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of d…A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder attributes, allowing an attacker to construct a serialized delta that passes the deserializer whitelist and contains dunder attributes. When processed, this can be exploited to access other modules, classes, and instances, leading to arbitrary attribute write and total RCE on any self-hosted pytorch-lightning application in its default configuration, as the delta endpoint is enabled by default. |
CVE-2024-7029 | HIGH | 8.7 | 0.38998 | 48.45 | No | No | 2024-08-02 | 2025-01-09 | euvd | Commands can be injected over the network and executed without authentication.Commands can be injected over the network and executed without authentication. |
CVE-2022-24627 | CRITICAL | 9.8 | 0.26389 | 48.44 | No | No | 2023-05-29 | 2025-01-14 | euvd | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parame…An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form. |
CVE-2022-46443 | HIGH | 8.8 | 0.37729 | 48.41 | No | No | 2022-12-14 | 2025-04-22 | euvd | mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter. |
CVE-2016-8706 | HIGH | 8.1 | 0.45703 | 48.4 | No | No | 2017-01-06 | 2024-08-06 | euvd | An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary pro…An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution. |
CVE-2017-2805 | CRITICAL | 9.8 | 0.26248 | 48.39 | No | No | 2017-06-21 | 2024-08-05 | euvd | An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A sp…An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the device to trigger this vulnerability. |
CVE-2024-52046 | CRITICAL | 10.0 | 0.23932 | 48.38 | No | Yes | 2024-12-25 | 2025-08-02 | euvd, packetstorm | The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process
incoming serialized data but lacks the …The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process
incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows
attackers to exploit the deserialization process by sending specially crafted malicious serialized data,
potentially leading to remote code execution (RCE) attacks.
This issue affects MINA core versions 2.0.X, 2.1.X and 2.2.X, and will be fixed by the releases 2.0.27, 2.1.10 and 2.2.4.
It's also important to note that an application using MINA core library will only be affected if the IoBuffer#getObject() method is called, and this specific method is potentially called when adding a ProtocolCodecFilter instance using the ObjectSerializationCodecFactory class in the filter chain. If your application is specifically using those classes, you have to upgrade to the latest version of MINA core library.
Upgrading will not be enough: you also need to explicitly allow the classes the decoder will accept in the ObjectSerializationDecoder instance, using one of the three new methods:
/**
* Accept class names where the supplied ClassNameMatcher matches for
* deserialization, unless they are otherwise rejected.
*
* @param classNameMatcher the matcher to use
*/
public void accept(ClassNameMatcher classNameMatcher)
/**
* Accept class names that match the supplied pattern for
* deserialization, unless they are otherwise rejected.
*
* @param pattern standard Java regexp
*/
public void accept(Pattern pattern)
/**
* Accept the wildcard specified classes for deserialization,
* unless they are otherwise rejected.
*
* @param patterns Wildcard file name patterns as defined by
* {@link org.apache.commons.io.FilenameUtils#wildcardMatch(String, String) FilenameUtils.wildcardMatch}
*/
public void accept(String... patterns)
By default, the decoder will reject *all* classes that will be present in the incoming data.
Note: The FtpServer, SSHd and Vysper sub-project are not affected by this issue. |
CVE-2024-41163 | HIGH | 7.5 | 0.5249 | 48.37 | No | No | 2024-10-03 | 2024-12-18 | euvd | A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can le…A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. |
CVE-2017-5715 | MEDIUM | 5.6 | 0.74207 | 48.37 | No | Yes | 2018-01-04 | 2025-05-06 | euvd, packetstorm | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information…Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
CVE-2024-39280 | CRITICAL | 9.1 | 0.34167 | 48.36 | No | No | 2025-01-14 | 2025-01-14 | euvd | An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially…An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
CVE-2024-24724 | CRITICAL | 9.8 | 0.26089 | 48.33 | No | No | 2024-04-03 | 2024-08-16 | euvd | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution …Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization. |
CVE-2020-35948 | CRITICAL | 9.9 | 0.24937 | 48.33 | No | No | 2021-01-01 | 2024-08-04 | euvd | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to…An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump. |
CVE-2021-39352 | HIGH | 7.2 | 0.55729 | 48.31 | No | No | 2021-10-21 | 2025-02-14 | euvd | The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchT…The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution. |
CVE-2009-1547 | HIGH | 8.8 | 0.37436 | 48.3 | No | No | 2009-10-14 | 2025-01-21 | euvd | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a c…Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability." |
CVE-2019-1913 | CRITICAL | 9.8 | 0.25944 | 48.28 | No | No | 2019-08-07 | 2024-11-19 | euvd | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, r…Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS. |
CVE-2022-47071 | CRITICAL | 9.8 | 0.25905 | 48.27 | No | No | 2023-02-06 | 2025-03-26 | euvd | In NVS365 V01, the background network test function can trigger command execution.In NVS365 V01, the background network test function can trigger command execution. |
CVE-2023-30013 | CRITICAL | 9.8 | 0.25889 | 48.26 | No | No | 2023-05-05 | 2025-01-29 | euvd | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. Thi…TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter. |
CVE-2026-41176 | CRITICAL | 9.2 | 0.32715 | 48.25 | No | Yes | 2026-04-22 | 2026-07-15 | euvd, packetstorm | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` …Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue. |
CVE-2018-15958 | CRITICAL | 9.8 | 0.25856 | 48.25 | No | No | 2018-09-25 | 2025-05-06 | euvd | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untru…Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution. |
CVE-2018-15965 | CRITICAL | 9.8 | 0.25856 | 48.25 | No | No | 2018-09-25 | 2025-05-06 | euvd | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untru…Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution. |
CVE-2018-15959 | CRITICAL | 9.8 | 0.25856 | 48.25 | No | No | 2018-09-25 | 2025-05-06 | euvd | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untru…Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution. |
CVE-2025-47269 | HIGH | 8.3 | 0.42958 | 48.24 | No | No | 2025-05-09 | 2025-05-10 | euvd | code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy …code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. Failure to properly validate the port for a proxy request can result in proxying to an arbitrary domain. The malicious URL `https://<code-server>/proxy/test@evil.com/path` would be proxied to `test@evil.com/path` where the attacker could exfiltrate a user's session token. Any user who runs code-server with the built-in proxy enabled and clicks on maliciously crafted links that go to their code-server instances with reference to /proxy. Normally this is used to proxy local ports, however the URL can reference the attacker's domain instead, and the connection is then proxied to that domain, which will include sending cookies. With access to the session cookie, the attacker can then log into code-server and have full access to the machine hosting code-server as the user running code-server. This issue has been patched in version 4.99.4. |
CVE-2018-25032 | HIGH | 7.5 | 0.52063 | 48.22 | No | No | 2022-03-25 | 2026-07-14 | euvd | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
CVE-2024-4701 | CRITICAL | 9.9 | 0.24629 | 48.22 | No | No | 2024-05-10 | 2024-08-01 | euvd | A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18 |
CVE-2016-0777 | MEDIUM | 6.5 | 0.63468 | 48.21 | No | No | 2016-01-14 | 2026-05-29 | euvd | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit…The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key. |