Latest CVE Feed
-
9.8
CRITICALCVE-2023-49238
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, i... Read more
Affected Products : enterprise- Published: Jan. 09, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2023-0980
A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/registrations/update_status.php of the component Status Update Handler. The manipulatio... Read more
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6919
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection.This issue affects NACPremium: through 01082024.... Read more
Affected Products : nacpremium- Published: Sep. 02, 2024
- Modified: Sep. 17, 2024
-
9.8
CRITICALCVE-2022-28397
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and publishe... Read more
Affected Products : ghost- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14742
Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.... Read more
Affected Products : nfsaxe- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28417
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.... Read more
Affected Products : home_owners_collection_management_system- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34149
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.... Read more
Affected Products : wp_oauth_server- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26279
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.... Read more
Affected Products : eyoucms- Published: Mar. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27651
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.... Read more
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36622
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a mal... Read more
Affected Products : online_covid_vaccination_scheduler_system- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28617
A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.... Read more
Affected Products : oneview- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49677
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : job_portal- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4441
A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The manipulation of the argument sheduleda... Read more
Affected Products : free_hospital_management_system_for_small_practices- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-46049
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2023-23489
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.... Read more
Affected Products : easy_digital_downloads- Published: Jan. 20, 2023
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-44838
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.... Read more
Affected Products : rapidcms- Published: Sep. 06, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2020-18261
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.... Read more
Affected Products : ed01-cms- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4325
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20469
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.... Read more
Affected Products : sahi_pro- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44808
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.... Read more
- Published: Oct. 16, 2023
- Modified: Nov. 21, 2024