Latest CVE Feed
-
9.8
CRITICALCVE-2022-2143
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.... Read more
Affected Products : iview- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30349
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.... Read more
Affected Products : jfinal_cms- Published: Apr. 27, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2024-45216
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL pa... Read more
Affected Products : solr- Published: Oct. 16, 2024
- Modified: Jul. 01, 2025
-
9.8
CRITICALCVE-2024-45265
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.... Read more
Affected Products : arfa-cms- Published: Aug. 26, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-24002
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct ... Read more
Affected Products : jsherp- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1527
Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webs... Read more
Affected Products : cms_made_simple- Published: Mar. 12, 2024
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2024-24330
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.... Read more
- Published: Jan. 30, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-1711
The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S... Read more
Affected Products : create- Published: Mar. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24525
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.... Read more
Affected Products : epointwebbuilder- Published: Feb. 29, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-24797
Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3. ... Read more
- Published: Feb. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-20017
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Is... Read more
- Published: Mar. 04, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-2056
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on T... Read more
Affected Products :- Published: Mar. 05, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-18175
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.... Read more
Affected Products : metinfo- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-7158
OX App Suite 7.10.0 and earlier has Incorrect Access Control.... Read more
Affected Products : open-xchange_appsuite- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25830
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit... Read more
- Published: Feb. 29, 2024
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2020-18262
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.... Read more
Affected Products : ed01-cms- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31672
In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.... Read more
- Published: Jun. 15, 2023
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2021-25916
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : patchmerge- Published: Mar. 16, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-23789
Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.... Read more
Affected Products :- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-47902
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of a... Read more
- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024