Latest CVE Feed
-
9.8
CRITICALCVE-2023-3003
A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_prices.php of the component GET Parameter Handler. The manipulation of the... Read more
Affected Products : train_station_ticketing_system- Published: May. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31874
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.... Read more
- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31951
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type.... Read more
Affected Products : rescue_dispatch_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25307
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."... Read more
Affected Products : cinema_seat_reservation_system- Published: Feb. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-43187
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.... Read more
Affected Products : nodebb- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-56801
Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.... Read more
Affected Products : tasklists- Published: Dec. 30, 2024
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2023-43216
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.... Read more
Affected Products : seacms- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13354
The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6.... Read more
Affected Products : strong_password- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0787
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections... Read more
Affected Products : limit_login_attempts- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6333
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be c... Read more
Affected Products : nuclide- Published: Dec. 31, 2018
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2020-36034
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.... Read more
Affected Products : school_faculty_scheduling_system- Published: Aug. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3693
A vulnerability classified as critical was found in SourceCodester Life Insurance Management System 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be ini... Read more
Affected Products : life_insurance_management_system- Published: Jul. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-3615
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper enum values used to check the frame subtype in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Elec... Read more
Affected Products : qca6574au_firmware sdx55_firmware sdm660_firmware sm8150_firmware msm8996au_firmware apq8096au_firmware mdm9150_firmware qca6174a_firmware qca9377_firmware qcs605_firmware +40 more products- Published: Jun. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0789
Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. ... Read more
Affected Products : phpmyfaq- Published: Feb. 12, 2023
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2024-25525
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2020-29061
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN... Read more
Affected Products : 72408a_firmware 9008a_firmware 9016a_firmware 92408a_firmware 92416a_firmware 9288_firmware 97016_firmware 97024p_firmware 97028p_firmware 97042p_firmware +46 more products- Published: Nov. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40212
An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service.... Read more
Affected Products : potplayer- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0256
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /fos/admin/ajax.php?action=login of the component Login Page. The manipulation of the argument Use... Read more
- Published: Jan. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3993
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. ... Read more
Affected Products : kavita- Published: Nov. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26634
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these ... Read more
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024