Latest CVE Feed
-
9.8
CRITICALCVE-2024-7583
A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the function formApPortalOneKeyAuth of the file /goform/apPortalOneKeyAuth. The manipulation of the argument data leads to buffer overflow. Th... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-7585
A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. The manipulation of the argument webUserName/webUserPassword leads t... Read more
- Published: Aug. 07, 2024
- Modified: Sep. 11, 2024
-
9.8
CRITICALCVE-2021-27417
eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflo... Read more
Affected Products : ecospro- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23898
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.... Read more
Affected Products : mcms- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6042
A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. T... Read more
Affected Products : real_estate_management_system- Published: Jun. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8130
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 24, 2024
- Modified: Aug. 27, 2024
-
9.8
CRITICALCVE-2024-6196
A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument username leads to sql injection. The att... Read more
Affected Products : banking_management_system_project_in_php- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8228
A vulnerability was found in Tenda O5 1.0.0.8(5017). It has been classified as critical. This affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument remark/type/time leads to stack-based buffer ove... Read more
- Published: Aug. 28, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2023-29734
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.... Read more
Affected Products : edjing_mix- Published: May. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8340
A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible... Read more
Affected Products : electric_billing_management_system- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-6372
A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The manipulation of the argument fullname/address/phonenumber/sex/email/city/comment le... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30015
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.... Read more
Affected Products : judging_management_system- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2024-8911
The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex... Read more
Affected Products : latepoint- Published: Oct. 08, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2024-6847
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.... Read more
- Published: Aug. 20, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-6890
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.... Read more
Affected Products : journyx- Published: Aug. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7108
Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.... Read more
Affected Products : cybermath- Published: Sep. 26, 2024
- Modified: Oct. 03, 2024
-
9.8
CRITICALCVE-2024-7350
The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to authentication bypass in versions 1.1.6 to 1.1.7. This is due to the plugin not properly verifying a user's identity prior to logging... Read more
Affected Products : bookingpress- Published: Aug. 08, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2023-6885
A vulnerability was found in Tongda OA 2017 up to 11.10. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file general/vote/manage/delete.php. The manipulation of the argument DELETE_STR leads to sql inje... Read more
Affected Products : tongda_office_anywhere- Published: Dec. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6902
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. The manipulation of the argument file leads to unrestricted upload. The expl... Read more
Affected Products : stupid_simple_cms- Published: Dec. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7311
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file register.php. The manipulation of the argument Email leads to sql injection. The attack may b... Read more
Affected Products : online_bus_reservation_site- Published: Jul. 31, 2024
- Modified: Aug. 13, 2024