Latest CVE Feed
-
9.8
CRITICALCVE-2024-51252
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-5118
A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection. The... Read more
- Published: May. 20, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-28713
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.... Read more
Affected Products :- Published: Mar. 28, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21473
Memory corruption while redirecting log file to any file location with any file name.... Read more
- Published: Apr. 01, 2024
- Modified: Jan. 13, 2025
-
9.8
CRITICALCVE-2023-7127
A vulnerability classified as critical was found in code-projects Automated Voting System 1.0. This vulnerability affects unknown code of the component Login. The manipulation of the argument idno leads to sql injection. The exploit has been disclosed to ... Read more
Affected Products : automated_voting_system- Published: Dec. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39673
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0446
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264528... Read more
Affected Products : android- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48659
An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.... Read more
Affected Products :- Published: Oct. 21, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2024-2941
A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /adminpanel/admin/query/loginExe.php. The manipulation of the argument pass lead... Read more
Affected Products : online_examination_system- Published: Mar. 27, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2024-48694
File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.... Read more
Affected Products :- Published: Nov. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48784
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-21653
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a p... Read more
Affected Products : vantage6- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-52439
Deserialization of Untrusted Data vulnerability in Mark O’Donnell Team Rosters allows Object Injection.This issue affects Team Rosters: from n/a through 4.6.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45132
NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 and prior to version 1.6 allows someone to bypass the WAF when a malicious `X-Forwarded-For` IP matches `IgnoreIP` `IgnoreCIDR` rules. T... Read more
Affected Products : naxsi- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21764
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port. ... Read more
Affected Products : rapid_scada- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48871
The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before copying data to the stack, potentially allowing remote code e... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2023-4488
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the exe... Read more
Affected Products : dropbox_folder_share- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4873
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a kn... Read more
- Published: Jan. 11, 2023
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-41505
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : student_enrollment- Published: Mar. 13, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2022-24702
An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer... Read more
Affected Products : winaprs- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024