Latest CVE Feed
-
9.8
CRITICALCVE-2025-25456
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-28242
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-3458
A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack c... Read more
- Published: Apr. 08, 2024
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2024-41364
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php... Read more
Affected Products : phoniebox- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2018-0038
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Cassandra.... Read more
Affected Products : contrail_service_orchestration- EPSS Score: %0.49
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10423
A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file /student/project_selection/project_selection.php of the component Project Selection Page. The... Read more
- Published: Oct. 27, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-35661
Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2.... Read more
Affected Products : upload_fields_for_wpforms- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32310
An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.... Read more
Affected Products : ingredient_stock_management_system- EPSS Score: %0.34
- Published: Jul. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25371
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execu... Read more
Affected Products : ofbiz- EPSS Score: %1.44
- Published: Sep. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8547
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, watchOS... Read more
- EPSS Score: %1.00
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10542
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and inc... Read more
- Published: Nov. 26, 2024
- Modified: Jul. 12, 2025
-
9.8
CRITICALCVE-2025-28035
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-37372
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database.... Read more
Affected Products : ruggedcom_crossbow- EPSS Score: %0.68
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41616
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-41623
An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload... Read more
- Published: Aug. 13, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2025-29909
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and pr... Read more
Affected Products : cryptolib- Published: Mar. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29913
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer o... Read more
Affected Products : cryptolib- Published: Mar. 17, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2022-25505
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.... Read more
Affected Products : taocms- EPSS Score: %0.23
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37628
Online Piggery Management System 1.0 is vulnerable to SQL Injection.... Read more
Affected Products : simple_online_piggery_management_system- EPSS Score: %0.22
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37702
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.... Read more
- EPSS Score: %0.12
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024