Latest CVE Feed
-
9.8
CRITICALCVE-2020-15889
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.... Read more
Affected Products : lua- Published: Jul. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8508
nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.... Read more
Affected Products : malware_cleaner- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-125082
A vulnerability was found in nivit redports. It has been declared as critical. This vulnerability affects unknown code of the file redports-trac/redports/model.py. The manipulation leads to sql injection. The name of the patch is fc2c1ea1b8d795094abb15ac7... Read more
Affected Products : redports- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28303
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.... Read more
Affected Products :- Published: Mar. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11887
SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.... Read more
Affected Products : simplybook- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12757
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated G... Read more
Affected Products : vault- Published: Jun. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4193
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.... Read more
Affected Products : security_guardium- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.... Read more
Affected Products : on_demand_marketplace_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-18634
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.... Read more
Affected Products : newspaper- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3727
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes conta... Read more
Affected Products : oh_my_zsh- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.... Read more
Affected Products : bus_booking_script- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-35314
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.... Read more
Affected Products : wondercms- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21784
An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22480
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.... Read more
Affected Products : harmonyos- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17198
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML ... Read more
Affected Products : roller- Published: May. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6698
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are man... Read more
- Published: Aug. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17377
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.... Read more
Affected Products : questions- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-32318
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.... Read more
- Published: Apr. 17, 2024
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2018-17777
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. T... Read more
- Published: Dec. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-20378
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A... Read more
Affected Products : android- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024