Latest CVE Feed
-
9.8
CRITICALCVE-2022-31351
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=.... Read more
Affected Products : online_car_wash_booking_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37934
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.... Read more
Affected Products : ninja_forms- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-50459
Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stripe Donation and Payment Plugin: from n/a through 3.2.3.... Read more
Affected Products : aidwp- Published: Oct. 29, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2022-26869
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.... Read more
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5521
Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.... Read more
Affected Products : kernelsu- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48118
SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page.... Read more
Affected Products : iqcrm- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2018-11229
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48228
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during ... Read more
Affected Products : authentik- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10044
A vulnerability classified as critical was found in gophergala sqldump. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as 76db54e9073b5248b8863e71a63d66a32d567d21. It is recommended to apply a pat... Read more
Affected Products : sqldump- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10050
A vulnerability was found in brandonfire miRNA_Database_by_PHP_MySql. It has been declared as critical. This vulnerability affects the function __construct/select_single_rna/count_rna of the file inc/model.php. The manipulation leads to sql injection. The... Read more
Affected Products : mirna_database_by_php_mysql- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10062
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to addres... Read more
Affected Products : galaxy- Published: Jan. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25190
l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.... Read more
Affected Products : l8w8jwt- Published: Feb. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10086
A vulnerability, which was classified as critical, was found in OpenCycleCompass server-php. Affected is an unknown function of the file api1/login.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remo... Read more
Affected Products : server-php- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27165
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus... Read more
Affected Products : csz_cms- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10887
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of IPv6 connections.... Read more
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10921
This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.e... Read more
Affected Products : c-more_hmi_ea9_firmware ea9-pgmsw ea9-rhmi ea9-t10cl ea9-t10wcl ea9-t12cl ea9-t15cl ea9-t15cl-r ea9-t6cl ea9-t6cl-r +3 more products- Published: Jul. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-35879
An issue was discovered in the rulinalg crate through 2020-02-11 for Rust. There are incorrect lifetime-boundary definitions for RowMut::raw_slice and RowMut::raw_slice_mut.... Read more
Affected Products : rulinalg- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36480
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client... Read more
Affected Products : aerospike_java_client- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3003
A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_prices.php of the component GET Parameter Handler. The manipulation of the... Read more
Affected Products : train_station_ticketing_system- Published: May. 31, 2023
- Modified: Nov. 21, 2024