Latest CVE Feed
-
9.8
CRITICALCVE-2022-27007
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save().... Read more
Affected Products : njs- EPSS Score: %0.44
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10036
A vulnerability was found in kylebebak dronfelipe. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named 87405b74fe651892d79d0dff62ed17a7eaef6a60. It is re... Read more
Affected Products : dronfelipe- EPSS Score: %0.04
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10057
A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/class.securelogin.php of the component Password Reset Handler. The manipulation le... Read more
Affected Products : little_software_stats- EPSS Score: %0.06
- Published: Jan. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27104
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.... Read more
Affected Products : formalms- EPSS Score: %1.00
- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-38281
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.... Read more
- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34236
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country... Read more
- EPSS Score: %2.13
- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27128
An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.... Read more
Affected Products : zbzcms- EPSS Score: %0.41
- Published: Apr. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10068
A vulnerability classified as critical was found in danynab movify-j. This vulnerability affects the function getByMovieId of the file app/business/impl/ReviewServiceImpl.java. The manipulation of the argument movieId/username leads to sql injection. The ... Read more
Affected Products : movify-j- EPSS Score: %0.04
- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25217
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.... Read more
Affected Products : online_medicine_ordering_system- EPSS Score: %0.14
- Published: Feb. 14, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-25222
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.... Read more
Affected Products : task_manager_in_php_with_source_code- EPSS Score: %0.11
- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27157
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.... Read more
Affected Products : pearweb- EPSS Score: %0.34
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28811
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.... Read more
- EPSS Score: %0.44
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4851
Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.... Read more
Affected Products : memos- EPSS Score: %0.08
- Published: Dec. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26205
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.... Read more
Affected Products : marky- EPSS Score: %2.24
- Published: Mar. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31788
IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.... Read more
Affected Products : idealms- EPSS Score: %1.58
- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11422
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted... Read more
Affected Products : oncell_g3150-hspa_firmware oncell_g3150-hspa-t_firmware oncell_g3150-hspa-t oncell_g3150-hspa- EPSS Score: %0.23
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2722
A vulnerability was found in SourceCodester Simple Student Information System and classified as critical. This issue affects some unknown processing of the file manage_course.php. The manipulation of the argument id leads to sql injection. The attack may ... Read more
Affected Products : simple_student_information_system- EPSS Score: %0.29
- Published: Aug. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3183
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. ... Read more
- EPSS Score: %0.77
- Published: Dec. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15805
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connec... Read more
- EPSS Score: %0.24
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31937
Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.... Read more
- EPSS Score: %0.33
- Published: Sep. 22, 2022
- Modified: May. 27, 2025