Latest CVE Feed
-
9.8
CRITICALCVE-2021-21335
In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentica... Read more
Affected Products : spnego_http_authentication_module- EPSS Score: %0.42
- Published: Mar. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21463
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.... Read more
Affected Products : qam8295p_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware sa6155p_firmware sa8145p_firmware sa8150p_firmware sa8155p_firmware +222 more products- Published: Apr. 01, 2024
- Modified: Jan. 13, 2025
-
9.8
CRITICALCVE-2023-50989
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.... Read more
- EPSS Score: %1.24
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-50988
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.... Read more
- EPSS Score: %0.12
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3422
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass... Read more
Affected Products : tooljet- EPSS Score: %0.14
- Published: Oct. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-30868
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.... Read more
- Published: Apr. 01, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2017-15580
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .htm... Read more
Affected Products : osticket- EPSS Score: %38.44
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-39226
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerabilit... Read more
Affected Products : mt6000_firmware mt6000 a1300_firmware a1300 x300b_firmware x300b ax1800_firmware ax1800 axt1800_firmware axt1800 +46 more products- Published: Aug. 06, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2021-1141
Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the De... Read more
- EPSS Score: %5.28
- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1343
PAM exposure enabling unauthenticated access to remote host... Read more
Affected Products : privileged_account_manager- EPSS Score: %0.47
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24142
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.... Read more
- EPSS Score: %1.45
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-51425
Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1. ... Read more
Affected Products : rencontre- Published: Apr. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2027
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it... Read more
Affected Products : zm_ajax_login_\&_register- EPSS Score: %0.25
- Published: Apr. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5119
A vulnerability was found in SourceCodester Event Registration System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php?f=load_registration. The manipulation of the argument last_id/event_id leads t... Read more
- Published: May. 20, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-0293
A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command in... Read more
- EPSS Score: %2.75
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6407
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.... Read more
- Published: Jul. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5076
An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG header-parser of the Accusoft ImageGear 19.3.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs... Read more
Affected Products : imagegear- EPSS Score: %2.25
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13392
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the rou... Read more
- EPSS Score: %2.15
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13433
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.... Read more
Affected Products : adminpanel- EPSS Score: %0.26
- Published: May. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29984
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.... Read more
Affected Products : simple_client_management_system- EPSS Score: %0.52
- Published: May. 12, 2022
- Modified: Nov. 21, 2024