Latest CVE Feed
-
9.8
CRITICALCVE-2021-30454
An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitialized memory buffer from KeyValueReader.... Read more
Affected Products : outer_cgi- EPSS Score: %0.43
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36993
The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.... Read more
Affected Products : travianz- EPSS Score: %0.10
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45012
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_bus_booking_system- EPSS Score: %0.10
- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29223
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MA... Read more
Affected Products : azure_rtos_usbx- EPSS Score: %5.35
- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40115
In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Feb. 15, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-52724
ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.... Read more
Affected Products : zzcms- Published: Dec. 02, 2024
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2025-20680
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418044... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-41506
An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
- Published: Feb. 27, 2024
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2024-5296
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerabi... Read more
Affected Products : d-view_8- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2022-29354
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : keystone- EPSS Score: %3.68
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21990
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials. ... Read more
Affected Products : ontap_select_deploy_administration_utility- Published: Apr. 17, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2023-23488
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.... Read more
Affected Products : paid_memberships_pro- EPSS Score: %78.83
- Published: Jan. 20, 2023
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2018-1000833
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.... Read more
Affected Products : zoneminder- EPSS Score: %1.98
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45338
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the routers/add-ticket.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_food_ordering_script- EPSS Score: %0.10
- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24830
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remot... Read more
Affected Products : openclinica- EPSS Score: %1.91
- Published: May. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40497
LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerabil... Read more
Affected Products : simple_editor- Published: May. 03, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-22205
Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the `location` variable and passes it to the `send` method which sends a `GET` request on lines 339-343 in `re... Read more
- EPSS Score: %0.30
- Published: Jan. 23, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33959
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-33961
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2022-2745
A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an unknown part of the file /admin/add_trainers.php of the component Add New Trainer. The manipulation of the argument trainer_name leads to... Read more
- EPSS Score: %0.23
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024