Latest CVE Feed
-
9.8
CRITICALCVE-2024-21653
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a p... Read more
Affected Products : vantage6- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-52439
Deserialization of Untrusted Data vulnerability in Mark O’Donnell Team Rosters allows Object Injection.This issue affects Team Rosters: from n/a through 4.6.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45132
NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 and prior to version 1.6 allows someone to bypass the WAF when a malicious `X-Forwarded-For` IP matches `IgnoreIP` `IgnoreCIDR` rules. T... Read more
Affected Products : naxsi- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21764
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port. ... Read more
Affected Products : rapid_scada- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48871
The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before copying data to the stack, potentially allowing remote code e... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2023-4488
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the exe... Read more
Affected Products : dropbox_folder_share- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4873
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a kn... Read more
- Published: Jan. 11, 2023
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-41505
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : student_enrollment- Published: Mar. 13, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2022-24702
An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer... Read more
Affected Products : winaprs- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45347
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the data... Read more
Affected Products : online_food_ordering_script- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45467
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.... Read more
- Published: Oct. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4558
A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file staff_data.php. The manipulation of the argument columns[0][data] leads to sql injec... Read more
- Published: Aug. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51405
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74. ... Read more
Affected Products : bookingpress- Published: Apr. 24, 2024
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2022-29514
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.... Read more
- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4973
A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument name/number/address leads to sql injection. The attack can be ini... Read more
Affected Products : simple_chat_system- Published: May. 16, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2025-4159
A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component GLOB Command Handler. The manipulation leads to buffer overflow. The attack can be lau... Read more
- Published: May. 01, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-40494
Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.... Read more
Affected Products : freecoap- Published: Oct. 22, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2021-31649
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute... Read more
Affected Products : jfinal- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-50488
An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.... Read more
- Published: Feb. 02, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2023-24642
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.... Read more
Affected Products : judging_management_system- Published: Mar. 03, 2023
- Modified: Mar. 07, 2025