CVE-2022-21993 | HIGH | 7.5 | 0.43618 | 45.27 | No | No | 2022-02-09 | 2025-01-02 | euvd | Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityWindows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
CVE-2024-43044 | HIGH | 8.8 | 0.28782 | 45.27 | No | No | 2024-08-07 | 2025-03-14 | euvd | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by…Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library. |
CVE-2024-40638 | HIGH | 8.1 | 0.36733 | 45.26 | No | No | 2024-11-15 | 2024-11-19 | euvd | GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of th…GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17. |
CVE-2024-43917 | CRITICAL | 9.3 | 0.22955 | 45.23 | No | No | 2024-08-29 | 2026-04-28 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishli…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2. |
CVE-2019-15984 | HIGH | 7.2 | 0.46935 | 45.23 | No | No | 2020-01-06 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote…Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one. |
CVE-2022-45768 | HIGH | 8.8 | 0.28662 | 45.23 | No | No | 2023-02-07 | 2025-03-25 | euvd | Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary…Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function. |
CVE-2024-30491 | HIGH | 8.5 | 0.32049 | 45.22 | No | No | 2024-03-29 | 2026-04-28 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affec…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. |
CVE-2025-54574 | CRITICAL | 9.3 | 0.22918 | 45.22 | No | No | 2025-08-01 | 2025-11-05 | euvd | Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code exec…Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions. |
CVE-2024-49368 | HIGH | 8.9 | 0.27475 | 45.22 | No | No | 2024-10-21 | 2024-11-01 | euvd | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not v…Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue. |
CVE-2024-27136 | MEDIUM | 6.1 | 0.5943 | 45.2 | No | No | 2024-06-24 | 2025-03-20 | euvd | XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensit…XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later. |
CVE-2022-40624 | CRITICAL | 9.8 | 0.17107 | 45.19 | No | No | 2022-12-20 | 2025-04-17 | euvd | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different …pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. |
CVE-2025-32583 | CRITICAL | 9.9 | 0.15977 | 45.19 | No | No | 2025-04-17 | 2026-04-28 | euvd | Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issu…Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0. |
CVE-2025-66398 | CRITICAL | 9.7 | 0.18231 | 45.18 | No | Yes | 2026-01-01 | 2026-01-05 | euvd, github | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollu…Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability. |
CVE-2025-59719 | CRITICAL | 9.1 | 0.25048 | 45.17 | No | No | 2025-12-09 | 2026-07-14 | euvd | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 t…An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message. |
CVE-2025-20265 | CRITICAL | 10.0 | 0.14777 | 45.17 | No | No | 2025-08-14 | 2026-02-26 | euvd | A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthentica…A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.
This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level.
Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both. |
CVE-2024-3848 | HIGH | 7.5 | 0.43284 | 45.15 | No | No | 2024-05-16 | 2024-08-01 | euvd | A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. Th…A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal. |
CVE-2020-6116 | HIGH | 8.8 | 0.28424 | 45.15 | No | No | 2020-09-17 | 2024-08-04 | euvd | An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawin…An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors. When using this allocated buffer, the application can write outside its bounds and cause memory corruption which can lead to code execution. A specially crafted document must be loaded by a victim in order to trigger this vulnerability. |
CVE-2022-22265 | MEDIUM | 5.0 | 0.00392 | 45.14 | Yes | No | 2022-01-07 | 2025-10-21 | cisa.gov, euvd | An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code…An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. |
CVE-2023-20048 | CRITICAL | 9.9 | 0.15821 | 45.14 | No | No | 2023-11-01 | 2025-12-16 | euvd | A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attac…A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configuration commands that are sent through the web service interface. An attacker could exploit this vulnerability by authenticating to the FMC web services interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute certain configuration commands on the targeted FTD device. To successfully exploit this vulnerability, an attacker would need valid credentials on the FMC Software. |
CVE-2019-12799 | MEDIUM | 6.5 | 0.54681 | 45.14 | No | No | 2019-06-13 | 2024-08-04 | euvd | In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, w…In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch. |
CVE-2024-30043 | MEDIUM | 6.5 | 0.54659 | 45.13 | No | No | 2024-05-14 | 2025-05-03 | euvd | Microsoft SharePoint Server Information Disclosure VulnerabilityMicrosoft SharePoint Server Information Disclosure Vulnerability |
CVE-2023-30149 | CRITICAL | 9.8 | 0.16904 | 45.12 | No | No | 2023-06-02 | 2025-01-31 | euvd | SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for P…SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via the type, input_name. or q parameter in the autocompletion.php front controller. |
CVE-2025-56005 | CRITICAL | 9.8 | 0.16903 | 45.12 | No | No | 2026-01-20 | 2026-08-07 | euvd, nvd | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` paramet…An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code via `__reduce__()`, an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet it is active in the PyPI version. This introduces a stealthy backdoor and persistence risk. NOTE: A third-party states that this vulnerability should be rejected because the proof of concept does not demonstrate arbitrary code execution and fails to complete successfully. |
CVE-2024-55661 | HIGH | 8.7 | 0.29497 | 45.12 | No | No | 2024-12-13 | 2024-12-13 | euvd | Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discov…Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the `Laravel\Pulse\Livewire\Concerns\RemembersQueries` trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application. An authenticated user with access to Laravel Pulse dashboard can execute arbitrary code by calling any function or static method in which the callable is a function or static method and the callable has no parameters or no strict parameter types. The vulnerable to component is `remember(callable $query, string $key = '')` method in `Laravel\Pulse\Livewire\Concerns\RemembersQueries`, and the vulnerability affects all Pulse card components that use this trait. Version 1.3.1 contains a patch. |
CVE-2022-47949 | CRITICAL | 9.8 | 0.16888 | 45.11 | No | No | 2022-12-24 | 2025-04-14 | euvd | The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execu…The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022. |
CVE-2023-21818 | HIGH | 7.5 | 0.43172 | 45.11 | No | No | 2023-02-14 | 2025-01-01 | euvd | Windows Secure Channel Denial of Service VulnerabilityWindows Secure Channel Denial of Service Vulnerability |
CVE-2021-26102 | CRITICAL | 9.8 | 0.16761 | 45.07 | No | No | 2024-12-19 | 2024-12-19 | euvd | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated …A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value. |
CVE-2025-2748 | MEDIUM | 6.1 | 0.59066 | 45.07 | No | No | 2025-03-24 | 2025-12-27 | cnvd, euvd | The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows …The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178. |
CVE-2025-4094 | CRITICAL | 9.8 | 0.16763 | 45.07 | No | No | 2025-05-21 | 2025-08-27 | euvd | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it …The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them. |
CVE-2023-22496 | HIGH | 8.1 | 0.36171 | 45.06 | No | Yes | 2023-01-14 | 2025-03-10 | euvd, packetstorm | Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a st…Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent. When an alert is triggered, the function `health_alarm_execute` is called. This function performs different checks and then enqueues a command by calling `spawn_enq_cmd`. This command is populated with several arguments that are not sanitized. One of them is the `registry_hostname` of the node for which the alert is raised. By providing a specially crafted `registry_hostname` as part of the health data that is streamed to a Netdata (parent) agent, an attacker can execute arbitrary commands at the remote host as a side-effect of the raised alert. Note that the commands are executed as the user running the Netdata Agent. This user is usually named `netdata`. The ability to run arbitrary commands may allow an attacker to escalate privileges by escalating other vulnerabilities in the system, as that user. The problem has been fixed in: Netdata agent v1.37 (stable) and Netdata agent v1.36.0-409 (nightly). As a workaround, streaming is not enabled by default. If you have previously enabled this, it can be disabled. Limiting access to the port on the recipient Agent to trusted child connections may mitigate the impact of this vulnerability. |
CVE-2025-44823 | CRITICAL | 9.9 | 0.15568 | 45.05 | No | No | 2025-10-07 | 2025-10-07 | euvd | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.ph…Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475. |
CVE-2024-2056 | CRITICAL | 9.8 | 0.16711 | 45.05 | No | No | 2024-03-05 | 2025-02-13 | euvd | Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, t…Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo. Using the tailon service, the contents of any file on the Artica Proxy can be viewed. |
CVE-2019-25224 | CRITICAL | 9.8 | 0.16682 | 45.04 | No | No | 2025-07-25 | 2026-04-08 | euvd | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vu…The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system. |
CVE-2024-29849 | CRITICAL | 9.8 | 0.16673 | 45.04 | No | No | 2024-05-22 | 2024-09-19 | euvd | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. |
CVE-2013-0006 | HIGH | 8.8 | 0.28084 | 45.03 | No | No | 2013-01-09 | 2025-01-16 | euvd | Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbi…Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability." |
CVE-2023-5642 | CRITICAL | 9.8 | 0.16652 | 45.03 | No | No | 2023-10-18 | 2024-09-13 | euvd | Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitiv…Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information. |
CVE-2025-34040 | CRITICAL | 10.0 | 0.1438 | 45.03 | No | No | 2025-06-24 | 2026-05-14 | euvd | An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId par…An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-01 UTC. |
CVE-2022-43604 | CRITICAL | 10.0 | 0.14372 | 45.03 | No | No | 2023-03-16 | 2025-03-05 | euvd | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer developm…An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability. |
CVE-2022-43605 | CRITICAL | 10.0 | 0.14372 | 45.03 | No | No | 2023-03-16 | 2024-08-03 | euvd | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer developm…An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability. |
CVE-2021-1388 | CRITICAL | 10.0 | 0.14359 | 45.03 | No | No | 2021-02-24 | 2024-11-08 | euvd | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an un…A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices. |
CVE-2023-25234 | CRITICAL | 9.8 | 0.16615 | 45.02 | No | No | 2023-02-27 | 2025-03-10 | euvd | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. |
CVE-2024-28739 | CRITICAL | 9.6 | 0.18921 | 45.02 | No | No | 2024-08-06 | 2024-08-06 | euvd | An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter. |
CVE-2022-41654 | CRITICAL | 9.6 | 0.18914 | 45.02 | No | No | 2022-12-23 | 2025-04-14 | euvd | An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-craf…An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability. |
CVE-2022-1680 | CRITICAL | 9.9 | 0.15471 | 45.01 | No | No | 2022-06-06 | 2024-08-03 | euvd | An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting f…An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account. |
CVE-2024-6235 | CRITICAL | 9.4 | 0.21168 | 45.01 | No | No | 2024-07-10 | 2025-04-23 | euvd | Sensitive information disclosure in NetScaler ConsoleSensitive information disclosure in NetScaler Console |
CVE-2023-3824 | CRITICAL | 9.4 | 0.21132 | 45.0 | No | No | 2023-08-11 | 2025-02-13 | euvd | In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entri…In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE. |
CVE-2023-47207 | CRITICAL | 9.8 | 0.16573 | 45.0 | No | No | 2023-11-30 | 2024-08-02 | euvd | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with l…In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges. |
CVE-2021-42727 | HIGH | 7.8 | 0.39401 | 44.99 | No | No | 2021-11-22 | 2024-09-17 | euvd | Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resu…Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge. |
CVE-2008-5180 | MEDIUM | 5.3 | 0.67977 | 44.99 | No | No | 2008-11-20 | 2024-10-15 | euvd | Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consump…Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions. |
CVE-2023-36812 | CRITICAL | 9.8 | 0.16501 | 44.98 | No | No | 2023-06-30 | 2025-02-13 | euvd | OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability …OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`. |