CVE-2019-6693
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 5 critical vulnerabilities and 69 high-priority updates requiring immediate attention.
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability - Active in CISA KEV catalog.
D-Link DIR-859 Router Path Traversal Vulnerability - Active in CISA KEV catalog.
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability - Active in CISA KEV catalog.
TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability - Active in CISA KEV catalog.
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Rails Ruby on Rails Path Traversal Vulnerability - Active in CISA KEV catalog.
PHPMailer Command Injection Vulnerability - Active in CISA KEV catalog.
Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability...
LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could po...
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore...
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and acc...
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14...
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9
A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1
A vulnerability was found in PHPGurukul Student Result Management System 2
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3
A vulnerability was found in PHPGurukul Hospital Management System 4
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9
The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability
A vulnerability was found in Tenda FH1202 1
A vulnerability classified as critical has been found in Tenda FH1202 1
A vulnerability classified as critical was found in Tenda FH1202 1
A vulnerability, which was classified as critical, has been found in Tenda FH1202 1
A vulnerability, which was classified as critical, was found in Tenda FH1202 1
A vulnerability has been found in Tenda FH1202 1
A vulnerability was found in Tenda AC1206 15
A vulnerability has been found in Tenda FH1201 1
A vulnerability was found in Tenda FH1201 1
A vulnerability was found in Tenda FH1201 1
A vulnerability was found in Tenda FH1201 1
A vulnerability was found in UTT HiPER 840G up to 3
A vulnerability classified as critical has been found in UTT HiPER 840G up to 3
A vulnerability was found in Tenda AC500 2
A vulnerability was found in Tenda FH1205 2
A vulnerability classified as critical has been found in Tenda AX1803 1
A vulnerability classified as critical was found in Tenda AX1803 1
Nix is a package manager for Linux and other Unix systems
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1
The Secure Password extension in One Identity Password Manager before 5
ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images
A vulnerability, which was classified as critical, has been found in code-projects Modern Bag 1
A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1
A vulnerability has been found in code-projects Modern Bag 1
A vulnerability was found in code-projects Modern Bag 1
A vulnerability was found in code-projects Modern Bag 1
A vulnerability was found in code-projects Modern Bag 1
A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1
A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1
A vulnerability was found in Jinher OA 1
A vulnerability was found in code-projects Job Diary 1
A vulnerability was found in Campcodes Sales and Inventory System 1
A vulnerability was found in Campcodes Sales and Inventory System 1
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1
A vulnerability has been found in code-projects Online Appointment Booking System 1
A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1
A vulnerability was found in code-projects Online Appointment Booking System 1
A vulnerability was found in code-projects Job Diary 1
A vulnerability was found in code-projects Job Diary 1
A vulnerability was found in code-projects Job Diary 1
A vulnerability was found in code-projects AVL Rooms 1
A vulnerability classified as critical has been found in code-projects AVL Rooms 1
A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1
A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1
A vulnerability has been found in code-projects Simple Shopping Cart 1
A vulnerability was found in code-projects Electricity Billing System 1
A vulnerability was found in code-projects Wedding Reservation 1
A vulnerability was found in code-projects Mobile Shop 1
SugarCRM before 13
A vulnerability was found in D-Link DI-8100 16
A vulnerability was found in D-Link DI-8100 16
Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software