Latest CVE Feed
-
9.8
CRITICALCVE-2023-35968
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigge... Read more
- EPSS Score: %0.24
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0536
A vulnerability, which was classified as critical, has been found in Tenda W9 1.0.0.7(4456). Affected by this issue is the function setWrlAccessList of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. T... Read more
- EPSS Score: %0.14
- Published: Jan. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31411
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam... Read more
Affected Products : sick_eventcam_app- EPSS Score: %0.16
- Published: Jun. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9852
An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer passwords are expected to be default or similar across install... Read more
Affected Products : sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_tripower_5000tl_firmware sunny_tripower_12000tl_firmware sunny_tripower_60_firmware sunny_boy_3000tl_firmware +68 more products- EPSS Score: %0.33
- Published: Aug. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-20402
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31424
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.... Read more
Affected Products : brocade_sannav- EPSS Score: %0.55
- Published: Aug. 31, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2022-20405
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31465
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x ... Read more
Affected Products : timekeeper- EPSS Score: %89.91
- Published: Jul. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31471
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side ve... Read more
Affected Products : gl-e750_firmware gl-mt3000_firmware gl-mt1300_firmware gl-mt300n-v2_firmware gl-ar750s_firmware gl-ar750_firmware gl-ar300m_firmware gl-b1300_firmware gl-a1300_firmware gl-ax1800_firmware +54 more products- EPSS Score: %0.50
- Published: May. 10, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2025-20055
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may execute an arbitrary OS command.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-0573
A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based... Read more
- EPSS Score: %0.44
- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0574
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sTime leads to stack-based buffer o... Read more
- EPSS Score: %0.43
- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-2046
A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The... Read more
Affected Products : best_employee_management_system- Published: Mar. 06, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-31710
TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.... Read more
- EPSS Score: %0.12
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24881
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and... Read more
Affected Products : codegen- EPSS Score: %4.70
- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36327
Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.... Read more
Affected Products : relic- EPSS Score: %0.11
- Published: Sep. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31902
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).... Read more
Affected Products : mobile_mouse- EPSS Score: %7.95
- Published: May. 17, 2023
- Modified: Jan. 22, 2025
-
9.8
CRITICALCVE-2023-31903
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.... Read more
Affected Products : guppy- EPSS Score: %4.28
- Published: May. 17, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2024-0649
A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the component Search. The manipulation of the argument url lead... Read more
Affected Products : zhihuiyun- EPSS Score: %0.06
- Published: Jan. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43058
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.10
- Published: Nov. 09, 2022
- Modified: May. 01, 2025