Latest CVE Feed
-
9.8
CRITICALCVE-2024-23761
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.... Read more
Affected Products : gambio- EPSS Score: %0.09
- Published: Feb. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25932
The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.... Read more
- EPSS Score: %0.18
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7602
node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function i... Read more
Affected Products : node-prompt-here- EPSS Score: %0.43
- Published: Mar. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10257
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_s... Read more
Affected Products : addons ozeum-museum chit_club-board_games yottis-simple_portfolio helion-agency_\&portfolio amuli nelson-barbershop_\+_tattoo_salon hallelujah-church right_way prider-pride_fest +53 more products- EPSS Score: %1.34
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33027
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.... Read more
Affected Products : singularity- EPSS Score: %0.61
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9580
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : magento- EPSS Score: %6.22
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0849
A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploi... Read more
- EPSS Score: %0.08
- Published: Feb. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7679
In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.... Read more
Affected Products : casperjs- EPSS Score: %0.77
- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5482
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the latest version. The vulnerability arises because the application does not adequately validate URLs entered by u... Read more
- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7714
All versions of package confucious are vulnerable to Prototype Pollution via the set function.... Read more
Affected Products : confucious- EPSS Score: %0.41
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3311
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only rele... Read more
Affected Products : october- EPSS Score: %1.52
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7727
All versions of package gedi are vulnerable to Prototype Pollution via the set function.... Read more
Affected Products : gedi- EPSS Score: %0.39
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23769
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.... Read more
- EPSS Score: %0.98
- Published: Oct. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30885
The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.... Read more
Affected Products : pyesasky- EPSS Score: %0.97
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0788
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. ... Read more
Affected Products : phpmyfaq- EPSS Score: %0.12
- Published: Feb. 12, 2023
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2023-4214
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.... Read more
Affected Products : apppresser- EPSS Score: %0.29
- Published: Nov. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7808
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.... Read more
- EPSS Score: %0.16
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24326
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.... Read more
- EPSS Score: %1.45
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34934
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 23, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2023-42283
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.... Read more
Affected Products : tyk- EPSS Score: %5.31
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024