Latest CVE Feed
-
9.8
CRITICALCVE-2024-20450
Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying... Read more
Affected Products : small_business_ip_phone_firmware spa_501g_firmware spa_502g_firmware spa_504g_firmware spa_508g_firmware spa_509g_firmware spa_512g_firmware spa_514g_firmware spa_525g_firmware spa_301_firmware +14 more products- Published: Aug. 07, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2022-23882
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.... Read more
Affected Products : tuzicms- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47873
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).... Read more
Affected Products : keos- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-51211
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject... Read more
Affected Products : opensis- Published: Nov. 08, 2024
- Modified: Jul. 17, 2025
-
9.8
CRITICAL- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-48008
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : limesurvey- Published: Jan. 27, 2023
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2024-9088
A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of the argument uname leads to buffer overflow. The exploit has been disclos... Read more
Affected Products : telecom_billing_management_system- Published: Sep. 22, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the lis... Read more
Affected Products : ac6_firmware ac10_firmware ac7_firmware ac1206_firmware ac5_firmware f1203_firmware ac8_firmware fh1203_firmware ac6 ac8 +6 more products- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39008
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.... Read more
Affected Products : opnsense- Published: Aug. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39073
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.... Read more
Affected Products : snmp_web_pro- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-48123
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delStaticDhcpRules function.... Read more
- Published: Jan. 20, 2023
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2022-48198
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depe... Read more
- Published: Jan. 01, 2023
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2023-43870
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certific... Read more
Affected Products : net2- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44009
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.... Read more
Affected Products : mojoportal- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27234
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.... Read more
Affected Products : openclinic_ga- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5046
A vulnerability was found in SourceCodester Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file registeracc.php. The manipulation of the argument email leads to sql injection. The attack may... Read more
Affected Products : online_examination_system- Published: May. 17, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-5057
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.... Read more
- Published: Aug. 29, 2024
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2022-48353
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.... Read more
- Published: Mar. 27, 2023
- Modified: Feb. 24, 2025
-
9.8
CRITICALCVE-2023-39439
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.... Read more
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2726
A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manipulation of the argument DID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disc... Read more
Affected Products : semcms- Published: Aug. 09, 2022
- Modified: Nov. 21, 2024