Latest CVE Feed
-
9.8
CRITICALCVE-2020-6068
An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker need... Read more
Affected Products : imagegear- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51644
Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is not required to exploit this vulnerability. ... Read more
Affected Products : allegra- Published: Nov. 22, 2024
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2024-2806
A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceId/deviceMac leads to stack-based buffe... Read more
- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2807
A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the argument filePath leads to stack-based buffer... Read more
- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46510
An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.... Read more
- Published: Oct. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25655
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.... Read more
Affected Products : basercms- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31856
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.... Read more
Affected Products : newsletter_module- Published: Jul. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36163
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the seriali... Read more
Affected Products : dubbo- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3481
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : woocommerce_dropshipping- Published: Nov. 07, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2023-46685
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.... Read more
- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46679
Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_job_portal- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-45494
An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe sh... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2022-30352
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.... Read more
Affected Products : phpabook- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15992
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.... Read more
Affected Products : website_broker_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-30357
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2021-38195
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.... Read more
Affected Products : libsecp256k1- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13818
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly w... Read more
- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38298
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.... Read more
Affected Products : manageengine_admanager_plus- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30413
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application.... Read more
Affected Products : covid_19_travel_pass_management_system- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34972
So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.... Read more
Affected Products : so_filter_shop_by- Published: Jul. 05, 2022
- Modified: Nov. 21, 2024