Latest CVE Feed
-
9.8
CRITICALCVE-2021-3757
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')... Read more
Affected Products : immer- EPSS Score: %0.12
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28797
A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following... Read more
- EPSS Score: %0.63
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29600
The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.... Read more
Affected Products : oelib- EPSS Score: %0.25
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43084
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.... Read more
- EPSS Score: %0.23
- Published: Mar. 24, 2022
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2022-30000
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.... Read more
- EPSS Score: %0.25
- Published: May. 12, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-30047
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.... Read more
Affected Products : mcms- EPSS Score: %0.36
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24711
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently ... Read more
Affected Products : codeigniter- EPSS Score: %0.41
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30518
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.... Read more
Affected Products : chatbot_application_with_a_suggestion_feature- EPSS Score: %0.29
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1896
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebook/hermes/commit/86543ac47e59c522976b5632b8bf9a2a4583c7d2) allows attackers to potentially execute arbitra... Read more
Affected Products : hermes- EPSS Score: %2.55
- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18761
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.... Read more
Affected Products : saltos- EPSS Score: %4.18
- Published: Nov. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44087
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.... Read more
Affected Products : attendance_and_payroll_system- EPSS Score: %21.48
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44093
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell... Read more
Affected Products : zrlog- EPSS Score: %4.52
- Published: Nov. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19110
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.... Read more
Affected Products : online_book_store_project_in_php- EPSS Score: %0.58
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44247
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary... Read more
- EPSS Score: %26.47
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44655
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on... Read more
Affected Products : online_pre-owned\/used_car_showroom_management_system- EPSS Score: %0.23
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39290
Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB37... Read more
- EPSS Score: %0.51
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44779
Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.... Read more
Affected Products : \[gwa\]_autoresponder- EPSS Score: %0.62
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39641
Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45411
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.... Read more
Affected Products : printable_staff_id_card_creator_system- EPSS Score: %3.21
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31132
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/cerdic/css-tidy/css_optimiser.php`. Access to the minifier is unrestricted and access may lead to Server-S... Read more
- EPSS Score: %0.34
- Published: Aug. 04, 2022
- Modified: Nov. 21, 2024