Latest CVE Feed
-
9.8
CRITICALCVE-2023-4634
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter f... Read more
Affected Products : media_library_assistant- EPSS Score: %92.43
- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25239
SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.... Read more
Affected Products : employee_management_system employee_management_system employee_management_system- Published: Mar. 21, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-29979
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.... Read more
Affected Products : simple_client_management_system- EPSS Score: %0.52
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29992
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=.... Read more
Affected Products : online_sports_complex_booking_system- EPSS Score: %0.25
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32522
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN and refer to recom... Read more
- EPSS Score: %0.24
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12118
An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager... Read more
Affected Products : open_network_automation_platform- EPSS Score: %1.15
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32513
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Mana... Read more
Affected Products : storage_manager- EPSS Score: %1.17
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32535
The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The referred vulnerability has been solved with the updated version of QSAN SAN... Read more
Affected Products : sanos- EPSS Score: %0.49
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30011
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.... Read more
Affected Products : hospital_management_system- EPSS Score: %1.62
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30048
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.... Read more
Affected Products : mcms- EPSS Score: %0.36
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12149
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.... Read more
- EPSS Score: %0.37
- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46527
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.... Read more
- EPSS Score: %0.37
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46545
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.... Read more
- EPSS Score: %0.22
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10238
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_en... Read more
Affected Products : bacnet_protocol_stack- EPSS Score: %0.52
- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3013
A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unknown part of the file /loginVaLidation.php. The manipulation of the argument login leads to sql injection. It is possible to initiate t... Read more
Affected Products : simple_task_managing_system- EPSS Score: %0.30
- Published: Aug. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-7095
Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.... Read more
Affected Products : exponent_cms- EPSS Score: %1.20
- Published: Nov. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2023-4662
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion.This issue affects Saphira Connect: before 9. ... Read more
Affected Products : connect- EPSS Score: %0.21
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26092
Liima before 1.17.28 allows server-side template injection.... Read more
Affected Products : liima- EPSS Score: %0.43
- Published: Feb. 20, 2023
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2022-33329
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger ... Read more
- EPSS Score: %0.27
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9558
Multiple SQL injection vulnerabilities in SmartCMS v.2.... Read more
Affected Products : smartcms- EPSS Score: %2.74
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025