Latest CVE Feed
-
9.8
CRITICALCVE-2023-3791
A vulnerability was found in IBOS OA 4.5.5 and classified as critical. Affected by this issue is the function actionExport of the file ?r=contact/default/export of the component Personal Office Address Book. The manipulation leads to sql injection. The at... Read more
Affected Products : ibos- EPSS Score: %0.05
- Published: Jul. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4413
The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known PO... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1981
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing ... Read more
Affected Products : migration\,_backup\,_staging- Published: Feb. 29, 2024
- Modified: Jan. 16, 2025
-
9.8
CRITICALCVE-2020-6065
An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An... Read more
Affected Products : imagegear- EPSS Score: %2.88
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48226
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2022-32417
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.... Read more
Affected Products : pbootcms- EPSS Score: %42.67
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38026
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. ... Read more
- EPSS Score: %0.42
- Published: Aug. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-44550
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.... Read more
- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
9.8
CRITICALCVE-2023-3806
A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to la... Read more
Affected Products : house_rental_and_property_listing_php- EPSS Score: %0.08
- Published: Jul. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-10009
A vulnerability was found in DrAzraelTod pyChao and classified as critical. Affected by this issue is the function klauen/lesen of the file mod_fun/__init__.py. The manipulation leads to sql injection. The patch is identified as 9d8adbc07c384ba51c2583ce08... Read more
Affected Products : pychao- EPSS Score: %0.04
- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7508
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.... Read more
- EPSS Score: %0.26
- Published: Jun. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1921
A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remot... Read more
Affected Products : lightpicture- Published: Feb. 27, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2022-28368
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).... Read more
Affected Products : dompdf- EPSS Score: %68.93
- Published: Apr. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43201
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.... Read more
- EPSS Score: %1.91
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38386
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.... Read more
Affected Products : ninja_forms- Published: Jun. 19, 2024
- Modified: Apr. 07, 2025
-
9.8
CRITICALCVE-2023-43270
dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.... Read more
Affected Products : dst-admin- EPSS Score: %1.84
- Published: Sep. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-20450
Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying... Read more
Affected Products : small_business_ip_phone_firmware spa_501g_firmware spa_502g_firmware spa_504g_firmware spa_508g_firmware spa_509g_firmware spa_512g_firmware spa_514g_firmware spa_525g_firmware spa_301_firmware +14 more products- Published: Aug. 07, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2022-23882
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.... Read more
Affected Products : tuzicms- EPSS Score: %0.23
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47873
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).... Read more
Affected Products : keos- EPSS Score: %0.05
- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-51211
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject... Read more
Affected Products : opensis- Published: Nov. 08, 2024
- Modified: Jul. 17, 2025