Latest CVE Feed
-
9.8
CRITICALCVE-2023-23450
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual pas... Read more
- EPSS Score: %0.17
- Published: May. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17796
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel()... Read more
Affected Products : mushroom_content_management_system- EPSS Score: %0.26
- Published: Sep. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12736
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.... Read more
Affected Products : ktor- EPSS Score: %0.03
- Published: Oct. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37814
Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33272
An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).... Read more
Affected Products : monitoring- EPSS Score: %1.14
- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44974
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : emlog- EPSS Score: %14.30
- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17897
LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.... Read more
Affected Products : laquis_scada- EPSS Score: %11.04
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43291
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.... Read more
Affected Products : emlog- EPSS Score: %13.13
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33045
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.... Read more
Affected Products : qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sd_8_gen1_5g_firmware sd865_5g_firmware wcd9380_firmware +255 more products- EPSS Score: %0.21
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37635
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.... Read more
Affected Products : community-skeleton- EPSS Score: %8.78
- Published: Oct. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38078
Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be exec... Read more
Affected Products : movable_type- EPSS Score: %5.22
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38881
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.... Read more
Affected Products : d8s-archives- EPSS Score: %0.36
- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37203
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.... Read more
Affected Products : jfinal_cms- EPSS Score: %0.54
- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22897
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.... Read more
Affected Products : ap_pagebuilder- EPSS Score: %85.19
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18202
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom pa... Read more
- EPSS Score: %0.40
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-2733
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access v... Read more
Affected Products : jd_edwards_enterpriseone_tools- EPSS Score: %88.05
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-11025
An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18258
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.... Read more
Affected Products : bagecms- EPSS Score: %0.51
- Published: Oct. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41558
The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.... Read more
Affected Products : set_user- EPSS Score: %0.43
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44659
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerabi... Read more
Affected Products : gocd- EPSS Score: %1.99
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024