Latest CVE Feed
-
9.8
CRITICALCVE-2022-35490
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around t... Read more
Affected Products : zammad- Published: Aug. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35741
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin b... Read more
Affected Products : cloudstack- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20704
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServer... Read more
Affected Products : clusterpro_x clusterpro_x_singleserversafe expresscluster_x expresscluster_x_singleserversafe- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26326
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and cal... Read more
Affected Products : buddyforms- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4116
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-41496
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.... Read more
Affected Products : icms- Published: Oct. 13, 2022
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2022-36201
Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.... Read more
Affected Products : doctor\'s_appointment_system- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36273
Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.... Read more
- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2682
A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${I... Read more
Affected Products : caton_live- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2023-26311
A remote code execution vulnerability in the webview component of OPPO Store app. ... Read more
Affected Products : oppo_store- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26921
OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.... Read more
- Published: Apr. 04, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-26978
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.... Read more
- Published: Apr. 07, 2023
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2023-27016
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more
- Published: Apr. 07, 2023
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2023-27018
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more
- Published: Apr. 07, 2023
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2023-27040
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.... Read more
Affected Products : simple_image_gallery_web_app- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2022-36452
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the context of the appli... Read more
Affected Products : micollab- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-36663
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.... Read more
Affected Products : oxauth- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36711
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.... Read more
Affected Products : library_management_system- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37002
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.... Read more
- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37057
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.... Read more
- Published: Aug. 28, 2022
- Modified: Jan. 06, 2025