Latest CVE Feed
-
9.8
CRITICALCVE-2020-18164
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.... Read more
- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40121
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.... Read more
Affected Products : online_banking_system- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2022-45132
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 templ... Read more
Affected Products : lava- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2023-29924
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.... Read more
Affected Products : powerjob- Published: Apr. 21, 2023
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2023-30246
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the contestant_id parameter.... Read more
Affected Products : judging_management_system- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2021-21307
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in version... Read more
Affected Products : lucee_server- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29423
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.... Read more
Affected Products : countdown_builder- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40615
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45720
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function.... Read more
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2022-40864
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2022-40865
Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/... Read more
- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2021-45986
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-46502
Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php.... Read more
Affected Products : online_student_enrollment_system- Published: Jan. 13, 2023
- Modified: Apr. 07, 2025
-
9.8
CRITICALCVE-2023-31458
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial instal... Read more
Affected Products : mivoice_connect- Published: May. 24, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-31541
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.... Read more
Affected Products : ckeditor- Published: Jun. 13, 2023
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2022-47117
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.... Read more
- Published: Dec. 30, 2022
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2022-42039
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.... Read more
Affected Products : d8s-lists- Published: Oct. 11, 2022
- Modified: May. 19, 2025
-
9.8
CRITICALCVE-2023-32336
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.... Read more
- Published: May. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47853
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.... Read more
- Published: Jan. 17, 2023
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2023-3237
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to t... Read more
Affected Products : otcms- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024