CVE-2024-4547 | CRITICAL | 9.8 | 0.01895 | 39.86 | No | No | 2024-05-06 | 2024-08-01 | euvd | A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, wh…A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field |
CVE-2023-39424 | CRITICAL | 9.9 | 0.00737 | 39.86 | No | No | 2023-09-07 | 2024-09-26 | euvd | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary cont…A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. |
CVE-2023-25693 | CRITICAL | 9.8 | 0.01895 | 39.86 | No | No | 2023-02-24 | 2025-02-13 | euvd | Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
This issue affects Apache Airflow Sqoop Provider versions bef…Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. |
CVE-2025-4981 | CRITICAL | 9.9 | 0.00735 | 39.86 | No | No | 2025-06-20 | 2025-06-20 | euvd | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in …Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default. |
CVE-2023-41330 | CRITICAL | 9.8 | 0.01877 | 39.86 | No | No | 2023-09-06 | 2024-09-30 | euvd | knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page.
## Issue
On March 17th the vu…knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page.
## Issue
On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2 added a check `if (\strpos($filename, 'phar://') === 0)` in the `prepareOutput` function to resolve this CVE, however if the user is able to control the second parameter of the `generateFromHtml()` function of Snappy, it will then be passed as the `$filename` parameter in the `prepareOutput()` function. In the original vulnerability, a file name with a `phar://` wrapper could be sent to the `fileExists()` function, equivalent to the `file_exists()` PHP function. This allowed users to trigger a deserialization on arbitrary PHAR files. To fix this issue, the string is now passed to the `strpos()` function and if it starts with `phar://`, an exception is raised. However, PHP wrappers being case insensitive, this patch can be bypassed using `PHAR://` instead of `phar://`. A successful exploitation of this vulnerability allows executing arbitrary code and accessing the underlying filesystem. The attacker must be able to upload a file and the server must be running a PHP version prior to 8. This issue has been addressed in commit `d3b742d61a` which has been included in version 1.4.3. Users are advised to upgrade. Users unable to upgrade should ensure that only trusted users may submit data to the `AbstractGenerator->generate(...)` function. |
CVE-2025-31330 | CRITICAL | 9.9 | 0.00734 | 39.86 | No | No | 2025-04-08 | 2026-02-26 | euvd | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC…SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system. |
CVE-2023-43892 | CRITICAL | 9.8 | 0.01894 | 39.86 | No | No | 2023-10-02 | 2025-04-04 | euvd | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This …Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload. |
CVE-2018-11574 | CRITICAL | 9.8 | 0.01899 | 39.86 | No | No | 2018-06-14 | 2025-12-03 | euvd | Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information di…Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected. |
CVE-2024-29241 | CRITICAL | 9.9 | 0.00756 | 39.86 | No | No | 2024-03-28 | 2025-08-12 | euvd | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows rem…Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors. |
CVE-2023-31090 | CRITICAL | 9.9 | 0.00757 | 39.86 | No | No | 2024-04-24 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, …Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60. |
CVE-2024-21010 | CRITICAL | 9.9 | 0.00735 | 39.86 | No | No | 2024-04-16 | 2025-03-17 | euvd | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). …Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). |
CVE-2023-3217 | HIGH | 8.8 | 0.13309 | 39.86 | No | No | 2023-06-13 | 2025-05-05 | euvd | Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a craf…Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2023-0022 | CRITICAL | 9.9 | 0.00743 | 39.86 | No | No | 2023-01-10 | 2025-04-09 | euvd | SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be ex…SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application. |
CVE-2025-9574 | CRITICAL | 9.9 | 0.00745 | 39.86 | No | No | 2025-10-20 | 2025-10-24 | euvd | Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .
All firmware ver…Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .
All firmware versions with the Serial Number from 2000 to 5166 |
CVE-2024-31705 | CRITICAL | 9.8 | 0.01883 | 39.86 | No | No | 2024-04-29 | 2025-11-04 | euvd | An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of us…An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input. |
CVE-2024-24707 | CRITICAL | 9.9 | 0.00748 | 39.86 | No | No | 2024-04-03 | 2026-04-28 | euvd | Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affec…Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2. |
CVE-2021-3878 | CRITICAL | 9.8 | 0.01886 | 39.86 | No | No | 2021-10-15 | 2024-08-03 | euvd | corenlp is vulnerable to Improper Restriction of XML External Entity Referencecorenlp is vulnerable to Improper Restriction of XML External Entity Reference |
CVE-2023-51972 | CRITICAL | 9.8 | 0.01894 | 39.86 | No | No | 2024-01-10 | 2024-09-03 | euvd | Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. |
CVE-2022-44006 | CRITICAL | 9.8 | 0.01877 | 39.86 | No | No | 2022-11-16 | 2025-04-30 | euvd | An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reac…An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file. |
CVE-2020-12782 | CRITICAL | 9.8 | 0.01886 | 39.86 | No | No | 2020-06-23 | 2024-09-17 | euvd | Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will…Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files. |
CVE-2024-54363 | CRITICAL | 9.8 | 0.01886 | 39.86 | No | No | 2024-12-16 | 2026-04-28 | euvd | Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue …Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0. |
CVE-2018-7791 | CRITICAL | 9.8 | 0.01896 | 39.86 | No | No | 2018-08-29 | 2026-05-29 | euvd | A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all version…A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this vulnerability and overwrite the password, the attacker can upload the original program from the PLC. |
CVE-2025-64721 | CRITICAL | 9.9 | 0.00706 | 39.85 | No | No | 2025-12-11 | 2025-12-15 | euvd | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the …Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt to sandboxed processes. The handler adds a fixed header size to a caller-controlled value_len without overflow checking. A large value_len (e.g., 0xFFFFFFF0) wraps the allocation size, causing a heap overflow when attacker data is copied into the undersized buffer. This allows sandboxed processes to execute arbitrary code as SYSTEM, fully compromising the host. This issue is fixed in version 1.16.7. |
CVE-2025-40597 | HIGH | 7.5 | 0.28132 | 39.85 | No | No | 2025-07-23 | 2026-02-26 | euvd | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Ser…A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. |
CVE-2025-29953 | CRITICAL | 9.8 | 0.01858 | 39.85 | No | No | 2025-04-18 | 2025-04-23 | euvd | Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.
This issue affects Apache ActiveMQ NMS OpenWire Cli…Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.
This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious responses that may eventually cause arbitrary code execution on the client. Version 2.1.0 introduced a allow/denylist feature to restrict deserialization, but this feature could be bypassed.
The .NET team has deprecated the built-in .NET binary serialization feature starting with .NET 9 and suggests migrating away from binary serialization. The project is considering to follow suit and drop this part of the NMS API altogether.
Users are recommended to upgrade to version 2.1.1, which fixes the issue. We also recommend to migrate away from relying on .NET binary serialization as a hardening method for the future. |
CVE-2025-49746 | CRITICAL | 9.9 | 0.00708 | 39.85 | No | No | 2025-07-18 | 2026-02-26 | euvd | Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
CVE-2024-56431 | CRITICAL | 9.8 | 0.01853 | 39.85 | No | No | 2024-12-25 | 2025-05-07 | euvd | oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by th…oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash. |
CVE-2022-45132 | CRITICAL | 9.8 | 0.01859 | 39.85 | No | No | 2022-11-18 | 2025-04-30 | euvd | In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 tem…In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server. |
CVE-2018-6487 | CRITICAL | 9.8 | 0.01867 | 39.85 | No | No | 2018-02-20 | 2024-09-17 | euvd | Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30…Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information. |
CVE-2022-25251 | CRITICAL | 9.8 | 0.01871 | 39.85 | No | No | 2022-03-16 | 2025-04-16 | euvd | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to se…When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and modify the affected product’s configuration. |
CVE-2022-31180 | CRITICAL | 9.8 | 0.0185 | 39.85 | No | No | 2022-08-01 | 2025-04-22 | euvd | Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when int…Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpolation` option set to `true`. The result is that if an attacker is able to include whitespace in their input they can: 1. Invoke shell-specific behaviour through shell-specific special characters inserted directly after whitespace. 2. Invoke shell-specific behaviour through shell-specific special characters inserted or appearing after line terminating characters. 3. Invoke arbitrary commands by inserting a line feed character. 4. Invoke arbitrary commands by inserting a carriage return character. Behaviour number 1 has been patched in [v1.5.7] which you can upgrade to now. No further changes are required. Behaviour number 2, 3, and 4 have been patched in [v1.5.8] which you can upgrade to now. No further changes are required. The best workaround is to avoid having to use the `interpolation: true` option - in most cases using an alternative is possible, see [the recipes](https://github.com/ericcornelissen/shescape#recipes) for recommendations. Alternatively, users may strip all whitespace from user input. Note that this is error prone, for example: for PowerShell this requires stripping `'\u0085'` which is not included in JavaScript's definition of `\s` for Regular Expressions. |
CVE-2022-41794 | CRITICAL | 9.8 | 0.01854 | 39.85 | No | No | 2022-12-23 | 2025-04-15 | euvd | A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PS…A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2026-54120 | CRITICAL | 9.9 | 0.00709 | 39.85 | No | No | 2026-07-23 | 2026-08-14 | euvd, nvd | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. |
CVE-2023-27586 | CRITICAL | 9.9 | 0.00722 | 39.85 | No | No | 2023-03-20 | 2025-02-25 | euvd | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when p…CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default. |
CVE-2026-21515 | CRITICAL | 9.9 | 0.00701 | 39.85 | No | No | 2026-04-24 | 2026-08-14 | euvd | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a n…Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. |
CVE-2025-54347 | CRITICAL | 9.9 | 0.00701 | 39.85 | No | No | 2025-11-24 | 2025-11-24 | euvd | A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows …A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary files under certain conditions. |
CVE-2021-22763 | CRITICAL | 9.8 | 0.01858 | 39.85 | No | No | 2021-06-11 | 2026-05-29 | euvd | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic …A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device. |
CVE-2023-29862 | CRITICAL | 9.8 | 0.01854 | 39.85 | No | No | 2023-05-15 | 2025-01-23 | euvd | An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel …An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters. |
CVE-2023-52333 | CRITICAL | 9.8 | 0.01854 | 39.85 | No | No | 2024-11-22 | 2024-11-25 | euvd | Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level.
The specific flaw exists within the saveFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE. Was ZDI-CAN-22548. |
CVE-2025-64663 | CRITICAL | 9.9 | 0.00721 | 39.85 | No | No | 2025-12-18 | 2026-04-16 | cnvd, euvd | Custom Question Answering Elevation of Privilege VulnerabilityCustom Question Answering Elevation of Privilege Vulnerability |
CVE-2021-38432 | CRITICAL | 9.8 | 0.0187 | 39.85 | No | No | 2021-10-15 | 2024-09-16 | euvd | FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-b…FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow an attacker to remotely execute code. |
CVE-2025-30841 | CRITICAL | 9.9 | 0.0072 | 39.85 | No | No | 2025-04-01 | 2026-04-29 | euvd | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builde…Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a through <= 2.8.8. |
CVE-2023-28753 | CRITICAL | 9.8 | 0.01851 | 39.85 | No | No | 2023-05-18 | 2025-01-21 | euvd | netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overfl…netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data. |
CVE-2020-13585 | CRITICAL | 9.8 | 0.01855 | 39.85 | No | No | 2021-02-10 | 2024-08-04 | euvd | An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A specially crafted malfo…An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2024-2360 | CRITICAL | 9.8 | 0.01869 | 39.85 | No | No | 2024-06-06 | 2024-08-01 | euvd | parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of use…parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' and 'PDF LaTeX path' settings. An attacker can exploit this vulnerability by manipulating these settings to execute arbitrary code on the targeted server. The issue affects the latest version of the software. The vulnerability stems from the application's handling of the 'discussion_db_name' and 'pdf_latex_path' parameters, which do not properly validate file paths, allowing for directory traversal. This vulnerability can also lead to further file exposure and other attack vectors by manipulating the 'discussion_db_name' parameter. |
CVE-2024-2221 | CRITICAL | 9.8 | 0.01845 | 39.85 | No | No | 2024-04-10 | 2024-08-01 | euvd | qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload`…qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwrite any file on the filesystem, leading to potential remote code execution. This issue affects the integrity and availability of the system, enabling unauthorized access and potentially causing the server to malfunction. |
CVE-2025-0070 | CRITICAL | 9.9 | 0.00701 | 39.85 | No | No | 2025-01-14 | 2025-01-14 | euvd | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by …SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability. |
CVE-2023-22647 | CRITICAL | 9.9 | 0.00715 | 39.85 | No | No | 2023-06-01 | 2025-01-09 | euvd | An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate K…An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local
cluster, resulting in the secret being deleted, but their read-level
permissions to the secret being preserved. When this operation was
followed-up by other specially crafted commands, it could result in the
user gaining access to tokens belonging to service accounts in the local cluster.
This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4. |
CVE-2024-52427 | CRITICAL | 9.9 | 0.00726 | 39.85 | No | No | 2024-11-18 | 2026-05-11 | euvd | Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Serv…Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11. |
CVE-2020-13561 | CRITICAL | 9.8 | 0.01855 | 39.85 | No | No | 2021-02-10 | 2024-08-04 | euvd | An out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to co…An out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. |