Latest CVE Feed
-
9.8
CRITICALCVE-2022-30885
The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.... Read more
Affected Products : pyesasky- EPSS Score: %0.97
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0788
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. ... Read more
Affected Products : phpmyfaq- EPSS Score: %0.12
- Published: Feb. 12, 2023
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2023-4214
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.... Read more
Affected Products : apppresser- EPSS Score: %0.29
- Published: Nov. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7808
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.... Read more
- EPSS Score: %0.16
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24326
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.... Read more
- EPSS Score: %1.45
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34934
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 23, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2023-42283
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.... Read more
Affected Products : tyk- EPSS Score: %5.31
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24324
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.... Read more
- EPSS Score: %0.10
- Published: Jan. 30, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2021-33216
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.... Read more
Affected Products : ruckus_iot_controller- EPSS Score: %23.00
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26437
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Is... Read more
- EPSS Score: %1.45
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-50713
SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.... Read more
Affected Products : smart_agent- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2021-33318
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the intern... Read more
- EPSS Score: %0.70
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26479
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.... Read more
- EPSS Score: %0.79
- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24496
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.... Read more
Affected Products : daily_habit_tracker- EPSS Score: %30.87
- Published: Feb. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42494
EisBaer Scada - CWE-749: Exposed Dangerous Method or Function... Read more
Affected Products : eisbaer_scada- EPSS Score: %0.22
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2662
Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device.... Read more
- EPSS Score: %0.28
- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17658
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.... Read more
Affected Products : forticlient- EPSS Score: %0.39
- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24507
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) ... Read more
Affected Products : astra- EPSS Score: %44.20
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10723
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.... Read more
- EPSS Score: %0.48
- Published: May. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26676
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.... Read more
Affected Products : a\+hrd- EPSS Score: %0.80
- Published: Apr. 07, 2022
- Modified: Nov. 21, 2024