Latest CVE Feed
-
9.8
CRITICALCVE-2022-25495
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.... Read more
Affected Products : cuppacms- EPSS Score: %2.85
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10329
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.... Read more
Affected Products : photo_station- EPSS Score: %15.11
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.... Read more
Affected Products : roseonlinecms- EPSS Score: %5.45
- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2021-32608
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.... Read more
Affected Products : smartstore- EPSS Score: %6.82
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41313
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.... Read more
Affected Products : doris- Published: Mar. 12, 2024
- Modified: Jun. 30, 2025
-
9.8
CRITICALCVE-2022-33325
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger ... Read more
- EPSS Score: %0.27
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9515
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : dozer- EPSS Score: %3.32
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-20395
NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.... Read more
- EPSS Score: %0.64
- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-54136
ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/upload.php where the user supplied input via collection ge... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2025-44831
EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.... Read more
Affected Products : engineercms- Published: May. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-4444
A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file vm\patient\edit-user.php. The manipulation of the argument i... Read more
Affected Products : free_hospital_management_system_for_small_practices- EPSS Score: %0.05
- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-14092
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.... Read more
Affected Products : paypal_pro- EPSS Score: %86.88
- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41449
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.... Read more
Affected Products : ajaxnewsticker- EPSS Score: %5.07
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2564
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.... Read more
Affected Products : mongoose- EPSS Score: %1.33
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29287
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.... Read more
Affected Products : car_rental_management_system- EPSS Score: %2.41
- Published: Dec. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41507
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.... Read more
Affected Products : super_store_finder- EPSS Score: %0.51
- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46741
CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive data from the logs which could allow them escalate privileges. CubeFS leaks configuration keys i... Read more
Affected Products : cubefs- EPSS Score: %0.04
- Published: Jan. 03, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23539
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.... Read more
Affected Products : fineract- Published: Mar. 29, 2024
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-41563
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.... Read more
- EPSS Score: %0.12
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41557
Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.... Read more
- EPSS Score: %0.12
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024