Latest CVE Feed
-
9.8
CRITICALCVE-2022-26628
Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.... Read more
Affected Products : matrimony- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26633
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.... Read more
Affected Products : simple_student_quarterly_result\/grade_system- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31106
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and pass it to `deep... Read more
Affected Products : underscore.deep- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8147
Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.... Read more
Affected Products : utils-extend- Published: Apr. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33578
Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and ... Read more
Affected Products : sharecare- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13096
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized acc... Read more
Affected Products : wallet- Published: Jul. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2097
A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php. The manipulation of the argument id leads to s... Read more
- Published: Apr. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-35441
FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.class.php.... Read more
Affected Products : fdcms- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26169
Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.... Read more
Affected Products : air_cargo_management_system- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31351
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=.... Read more
Affected Products : online_car_wash_booking_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37934
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.... Read more
Affected Products : ninja_forms- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-50459
Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stripe Donation and Payment Plugin: from n/a through 3.2.3.... Read more
Affected Products : aidwp- Published: Oct. 29, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2022-26869
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.... Read more
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5521
Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.... Read more
Affected Products : kernelsu- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48118
SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page.... Read more
Affected Products : iqcrm- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2018-11229
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48228
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during ... Read more
Affected Products : authentik- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10044
A vulnerability classified as critical was found in gophergala sqldump. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as 76db54e9073b5248b8863e71a63d66a32d567d21. It is recommended to apply a pat... Read more
Affected Products : sqldump- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10050
A vulnerability was found in brandonfire miRNA_Database_by_PHP_MySql. It has been declared as critical. This vulnerability affects the function __construct/select_single_rna/count_rna of the file inc/model.php. The manipulation leads to sql injection. The... Read more
Affected Products : mirna_database_by_php_mysql- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10062
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to addres... Read more
Affected Products : galaxy- Published: Jan. 17, 2023
- Modified: Nov. 21, 2024