Latest CVE Feed
-
9.8
CRITICALCVE-2023-27040
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.... Read more
Affected Products : simple_image_gallery_web_app- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2022-36452
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the context of the appli... Read more
Affected Products : micollab- Published: Oct. 25, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-36663
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.... Read more
Affected Products : oxauth- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36711
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.... Read more
Affected Products : library_management_system- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37002
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.... Read more
- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37057
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.... Read more
- Published: Aug. 28, 2022
- Modified: Jan. 06, 2025
-
9.8
CRITICALCVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php end... Read more
- Published: Aug. 18, 2022
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2022-37258
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.... Read more
Affected Products : steal- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37266
Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.... Read more
Affected Products : steal- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22208
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.... Read more
Affected Products : 74cms- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22276
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.... Read more
Affected Products : weforms- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4274
A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of the file /view-property.php. The manipulation of the argument property_id leads to sql injection. It is possible to launch the attack r... Read more
Affected Products : house_rental_system- Published: Dec. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22807
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.... Read more
Affected Products : vtiger_crm- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38823
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2887
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. ... Read more
- Published: May. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44003
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.... Read more
Affected Products : backclick- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-44118
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.... Read more
Affected Products : dedecmsv6- Published: Nov. 23, 2022
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2022-44180
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.... Read more
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44194
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-23877
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.... Read more
Affected Products : pdf2xml- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024