CVE-2018-1722 | CRITICAL | 10.0 | 0.09044 | 43.17 | No | No | 2018-08-24 | 2024-09-16 | euvd | IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation servi…IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370. |
CVE-2023-46257 | CRITICAL | 9.8 | 0.11337 | 43.17 | No | No | 2023-12-19 | 2025-05-06 | euvd | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of…An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. |
CVE-2023-2928 | MEDIUM | 6.3 | 0.51351 | 43.17 | No | No | 2023-05-27 | 2025-01-13 | euvd | A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functiona…A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083. |
CVE-2025-9501 | CRITICAL | 9.0 | 0.20473 | 43.17 | No | No | 2025-11-17 | 2025-11-17 | euvd | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthe…The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post. |
CVE-2022-0819 | HIGH | 7.2 | 0.4101 | 43.15 | No | No | 2022-03-02 | 2024-08-02 | euvd | Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1. |
CVE-2023-3124 | HIGH | 8.8 | 0.2272 | 43.15 | No | No | 2023-06-07 | 2026-04-08 | euvd | The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_…The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation. |
CVE-2023-32562 | MEDIUM | 6.8 | 0.45562 | 43.15 | No | No | 2023-08-10 | 2025-03-06 | euvd | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker t…An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1. |
CVE-2025-13184 | CRITICAL | 9.8 | 0.11278 | 43.15 | No | No | 2025-12-10 | 2025-12-10 | cnvd, euvd | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset…Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected. |
CVE-2020-36155 | CRITICAL | 10.0 | 0.08975 | 43.14 | No | No | 2021-01-04 | 2024-08-04 | euvd | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. A…An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access. |
CVE-2014-0754 | CRITICAL | 10.0 | 0.08978 | 43.14 | No | No | 2014-10-03 | 2025-08-25 | euvd | Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Ex…Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request. |
CVE-2024-55547 | CRITICAL | 9.3 | 0.1694 | 43.13 | No | No | 2024-12-10 | 2025-11-03 | euvd | SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. |
CVE-2018-1612 | MEDIUM | 5.8 | 0.56952 | 43.13 | No | No | 2018-07-17 | 2024-09-16 | euvd | IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive inf…IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164. |
CVE-2022-34258 | MEDIUM | 4.8 | 0.68332 | 43.12 | No | No | 2022-08-16 | 2025-04-23 | euvd | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting…Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. |
CVE-2024-52765 | CRITICAL | 9.8 | 0.11208 | 43.12 | No | No | 2024-11-20 | 2025-03-13 | euvd | H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. |
CVE-2023-23489 | CRITICAL | 9.8 | 0.11172 | 43.11 | No | No | 2023-01-20 | 2025-04-03 | euvd | The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in th…The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action. |
CVE-2017-8817 | CRITICAL | 9.8 | 0.11175 | 43.11 | No | No | 2017-11-29 | 2026-04-15 | euvd | The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and app…The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character. |
CVE-2023-0017 | CRITICAL | 9.4 | 0.15729 | 43.11 | No | No | 2023-01-10 | 2025-04-09 | euvd | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and…An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable. |
CVE-2020-10881 | CRITICAL | 9.8 | 0.11177 | 43.11 | No | No | 2020-03-25 | 2024-08-04 | euvd | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1…This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9660. |
CVE-2023-22523 | CRITICAL | 9.8 | 0.11147 | 43.1 | No | No | 2023-12-06 | 2026-02-25 | euvd | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery…This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent. |
CVE-2021-24078 | CRITICAL | 9.8 | 0.11155 | 43.1 | No | No | 2021-02-25 | 2024-08-03 | euvd | Windows DNS Server Remote Code Execution VulnerabilityWindows DNS Server Remote Code Execution Vulnerability |
CVE-2025-28146 | CRITICAL | 9.8 | 0.11106 | 43.09 | No | No | 2025-04-04 | 2025-04-15 | euvd | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url i…Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel |
CVE-2024-0919 | HIGH | 8.8 | 0.22549 | 43.09 | No | No | 2024-01-26 | 2024-10-18 | euvd | A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the com…A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
CVE-1999-0204 | HIGH | 10.0 | 0.08839 | 43.09 | No | No | 1999-09-29 | 2024-08-01 | euvd, nvd | Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. |
CVE-2024-21726 | MEDIUM | 6.5 | 0.48839 | 43.09 | No | No | 2024-02-20 | 2024-12-25 | euvd | Inadequate content filtering leads to XSS vulnerabilities in various components.Inadequate content filtering leads to XSS vulnerabilities in various components. |
CVE-2023-22884 | CRITICAL | 9.8 | 0.11082 | 43.08 | No | No | 2023-01-21 | 2025-03-31 | euvd | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airfl…Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0. |
CVE-2023-49105 | CRITICAL | 9.8 | 0.11074 | 43.08 | No | No | 2023-11-21 | 2024-08-29 | euvd | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication …An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0. |
CVE-2025-36527 | HIGH | 8.3 | 0.28216 | 43.08 | No | No | 2025-05-23 | 2025-05-23 | euvd | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. |
CVE-2018-5353 | CRITICAL | 9.8 | 0.1106 | 43.07 | No | No | 2020-09-29 | 2026-07-09 | euvd, nvd | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate…The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required |
CVE-2025-45988 | CRITICAL | 9.8 | 0.1106 | 43.07 | No | No | 2025-06-13 | 2025-06-13 | euvd | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450…Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cmd parameter in the bs_SetCmd function. |
CVE-2026-50518 | CRITICAL | 9.8 | 0.11058 | 43.07 | No | No | 2026-07-14 | 2026-08-10 | euvd, nvd | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
CVE-2023-0678 | HIGH | 7.5 | 0.37304 | 43.06 | No | No | 2023-02-04 | 2025-03-26 | euvd | Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1. |
CVE-2012-4775 | HIGH | 8.8 | 0.22444 | 43.06 | No | No | 2012-11-14 | 2025-01-16 | euvd | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka …Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreeNode Use After Free Vulnerability." |
CVE-2024-24578 | CRITICAL | 10.0 | 0.08739 | 43.06 | No | No | 2024-03-18 | 2024-08-26 | euvd | RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20…RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based `HMIPServer.jar` component. RaspberryMatric includes a Java based `HMIPServer`, that can be accessed through URLs starting with `/pages/jpages`. The `FirmwareController` class does however not perform any session id checks, thus this feature can be accessed without a valid session. Due to this issue, attackers can gain remote code execution as root user, allowing a full system compromise. Version 3.75.6.20240316 contains a patch. |
CVE-2025-53772 | HIGH | 8.8 | 0.22399 | 43.04 | No | No | 2025-08-12 | 2026-02-26 | euvd | Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. |
CVE-2025-0868 | CRITICAL | 9.3 | 0.1668 | 43.04 | No | No | 2025-02-20 | 2025-10-03 | euvd | A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eva…A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint..
This issue affects DocsGPT: from 0.8.1 through 0.12.0. |
CVE-2023-2071 | CRITICAL | 9.8 | 0.10974 | 43.04 | No | No | 2023-09-12 | 2024-09-25 | euvd | Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated a…Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to execute exported functions from libraries. There is a routine that restricts it to execute specific functions from two dynamic link library files. By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function. |
CVE-2023-22501 | CRITICAL | 9.4 | 0.15533 | 43.04 | No | No | 2023-02-01 | 2024-10-01 | euvd | An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate ano…An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases:
* If the attacker is included on Jira issues or requests with these users, or
* If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users.
Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account. |
CVE-2020-11910 | CRITICAL | 9.8 | 0.10934 | 43.03 | No | No | 2020-06-17 | 2025-09-30 | euvd | The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read. |
CVE-2025-40598 | MEDIUM | 6.1 | 0.53214 | 43.02 | No | No | 2025-07-23 | 2025-07-29 | euvd | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker t…A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code. |
CVE-2026-50160 | CRITICAL | 10.0 | 0.08603 | 43.01 | No | No | 2026-07-01 | 2026-07-02 | euvd | Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthen…Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe is configured without whitelist: true, so extra properties on the request body that are not declared in SaveOnboardingConfigRequest are not stripped and are iterated in the service layer as if they were legitimate InfraConfig entries. Because keys such as JWT_SECRET and SESSION_SECRET are valid InfraConfigEnum values and are not explicitly rejected during validation, an unauthenticated attacker who can reach a fresh instance before onboarding completes (or when no users exist) can overwrite these values in the database. Overwriting JWT_SECRET gives the attacker control of the JWT signing key, allowing them to forge tokens for any user, including administrators, and results in full server compromise. The issue is fixed in hoppscotch 2026.5.0. |
CVE-2021-26701 | HIGH | 8.1 | 0.30315 | 43.01 | No | No | 2021-02-25 | 2026-05-28 | euvd | .NET Core Remote Code Execution Vulnerability.NET Core Remote Code Execution Vulnerability |
CVE-2024-6587 | HIGH | 7.5 | 0.37184 | 43.01 | No | No | 2024-09-13 | 2024-09-13 | euvd | A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the…A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST /chat/completions`, causing the application to send the request to the domain specified by `api_base`. This request includes the OpenAI API key. A malicious user can set the `api_base` to their own domain and intercept the OpenAI API key, leading to unauthorized access and potential misuse of the API key. |
CVE-2024-38666 | CRITICAL | 9.1 | 0.18881 | 43.01 | No | No | 2025-01-14 | 2025-01-15 | euvd | An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505…An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
CVE-2025-47188 | MEDIUM | 6.5 | 0.48579 | 43.0 | No | No | 2025-08-07 | 2025-09-15 | euvd | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Un…A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the phone, leading to disclosure or modification of sensitive configuration data or affecting device availability and operation. |
CVE-2022-38580 | CRITICAL | 9.8 | 0.10867 | 43.0 | No | No | 2022-10-24 | 2026-07-09 | euvd | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). |
CVE-2024-9014 | CRITICAL | 9.9 | 0.09685 | 42.99 | No | No | 2024-09-23 | 2024-09-23 | euvd | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to poten…pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data. |
CVE-2024-5411 | HIGH | 8.7 | 0.234 | 42.99 | No | No | 2024-05-28 | 2025-10-08 | euvd | Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.T…Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below. |
CVE-2022-25765 | HIGH | 7.3 | 0.39389 | 42.99 | No | No | 2022-09-09 | 2024-09-16 | euvd | The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. |
CVE-2024-0087 | CRITICAL | 9.0 | 0.1992 | 42.97 | No | No | 2024-05-09 | 2024-08-01 | euvd | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this fi…NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
CVE-2024-44466 | CRITICAL | 9.8 | 0.1073 | 42.96 | No | No | 2024-09-11 | 2024-09-11 | euvd | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/we…COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface. |