Latest CVE Feed
-
9.8
CRITICALCVE-2018-8027
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.... Read more
Affected Products : camel- EPSS Score: %2.97
- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27234
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminlog.asp, Archivemsgs.asp, Deletelog.asp, Eventlog.asp, and Evmlog.asp.... Read more
Affected Products : voice- EPSS Score: %0.37
- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23377
This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input saniti... Read more
Affected Products : onion-oled-js- EPSS Score: %0.61
- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37478
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.... Read more
- EPSS Score: %0.68
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41660
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.... Read more
Affected Products : patient_appointment_scheduler_system- EPSS Score: %0.26
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45691
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.... Read more
Affected Products : messagepack-rs- EPSS Score: %0.43
- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9374
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.... Read more
- EPSS Score: %88.70
- Published: Feb. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32337
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.... Read more
Affected Products : hospital\'s_patient_records_management_system- EPSS Score: %0.25
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28929
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.... Read more
Affected Products : hospital_management_system- EPSS Score: %0.21
- Published: May. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11673
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Tot... Read more
Affected Products : responsive_poll- EPSS Score: %2.48
- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29989
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.... Read more
Affected Products : online_sports_complex_booking_system- EPSS Score: %0.25
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30495
In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)... Read more
Affected Products : automotive_shop_management_system- EPSS Score: %0.36
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30476
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.... Read more
- EPSS Score: %0.39
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34601
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.... Read more
- EPSS Score: %0.44
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34613
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.... Read more
- EPSS Score: %1.77
- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10292
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be init... Read more
Affected Products : zzcms- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-35150
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : baijiacms- EPSS Score: %0.40
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35153
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.... Read more
Affected Products : fusionpbx- EPSS Score: %5.32
- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36695
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.... Read more
Affected Products : ingredients_stock_management_system- EPSS Score: %0.32
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36709
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.... Read more
Affected Products : library_management_system- EPSS Score: %0.32
- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024