Latest CVE Feed
-
9.8
CRITICALCVE-2020-11546
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.... Read more
Affected Products : superwebmailer- EPSS Score: %91.83
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34348
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR ... Read more
Affected Products : qvr- EPSS Score: %1.22
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27115
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.... Read more
- EPSS Score: %14.78
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27131
An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : zbzcms- EPSS Score: %0.90
- Published: Apr. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35327
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.... Read more
- EPSS Score: %0.44
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28106
Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.... Read more
Affected Products : online_sports_complex_booking_system- EPSS Score: %0.34
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2821
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.... Read more
Affected Products : nameless- EPSS Score: %0.28
- Published: Aug. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28422
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41288
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.... Read more
Affected Products : manageengine_opmanager- EPSS Score: %22.19
- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41317
XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.... Read more
Affected Products : xss_hunter_express- EPSS Score: %0.50
- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41392
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.... Read more
Affected Products : boostnote- EPSS Score: %7.06
- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28606
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.... Read more
Affected Products : bosscms- EPSS Score: %0.49
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41695
An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .... Read more
Affected Products : premiumdatingscript- EPSS Score: %0.26
- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41716
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function... Read more
Affected Products : mahavitaran- EPSS Score: %0.38
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41739
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.... Read more
Affected Products : artica_proxy- EPSS Score: %6.96
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28888
Spryker Commerce OS 1.4.2 allows Remote Command Execution.... Read more
Affected Products : cloud_commerce- EPSS Score: %3.39
- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28993
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.... Read more
Affected Products : multi_store_inventory_management_system- EPSS Score: %0.34
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18285
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an attacker to extrac... Read more
Affected Products : cmg_suite- EPSS Score: %0.62
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11815
In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.... Read more
Affected Products : rukovoditel- EPSS Score: %0.88
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37400
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.... Read more
- EPSS Score: %0.70
- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024