Latest CVE Feed
-
9.8
CRITICALCVE-2022-4274
A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of the file /view-property.php. The manipulation of the argument property_id leads to sql injection. It is possible to launch the attack r... Read more
Affected Products : house_rental_system- EPSS Score: %0.04
- Published: Dec. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22807
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.... Read more
Affected Products : vtiger_crm- EPSS Score: %0.26
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38823
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.... Read more
- EPSS Score: %0.13
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2887
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. ... Read more
- EPSS Score: %0.02
- Published: May. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44003
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.... Read more
Affected Products : backclick- EPSS Score: %0.07
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44118
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.... Read more
Affected Products : dedecmsv6- EPSS Score: %5.27
- Published: Nov. 23, 2022
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2022-44180
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.... Read more
- EPSS Score: %0.15
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44194
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.... Read more
- EPSS Score: %0.27
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-23877
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.... Read more
Affected Products : pdf2xml- EPSS Score: %0.46
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41589
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to ... Read more
- EPSS Score: %2.45
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13421
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.... Read more
Affected Products : openiam- EPSS Score: %0.33
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23978
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"... Read more
Affected Products : ecommerce_cms- EPSS Score: %0.87
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34057
The Scoptrial package in PyPI version v0.0.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : scoptrial- EPSS Score: %0.61
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44621
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.... Read more
Affected Products : kylin- EPSS Score: %0.70
- Published: Dec. 30, 2022
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2020-24202
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.... Read more
Affected Products : house_rental_and_property_listing_project- EPSS Score: %3.07
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-18164
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.... Read more
- EPSS Score: %0.26
- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40121
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.... Read more
Affected Products : online_banking_system- EPSS Score: %0.08
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2022-45132
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 templ... Read more
Affected Products : lava- EPSS Score: %6.46
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2023-29924
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.... Read more
Affected Products : powerjob- EPSS Score: %1.36
- Published: Apr. 21, 2023
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2023-30246
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the contestant_id parameter.... Read more
Affected Products : judging_management_system- EPSS Score: %0.93
- Published: May. 12, 2023
- Modified: Jan. 24, 2025