Latest CVE Feed
-
9.8
CRITICALCVE-2024-24327
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.... Read more
- Published: Jan. 30, 2024
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2024-50486
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through 1.0.5.... Read more
Affected Products : flutter_api- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50487
Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.... Read more
Affected Products : maanstore_api- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2022-22522
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.... Read more
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24543
Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.... Read more
- Published: Feb. 05, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2024-5063
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injectio... Read more
Affected Products : online_course_registration_system- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24561
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() functio... Read more
Affected Products : vyper- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5084
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthen... Read more
Affected Products : hash_form- Published: May. 23, 2024
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2021-41609
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection... Read more
Affected Products : selectsurvey.net- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5117
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The manipulation of the argument username/password leads to sql injection. It is possible to... Read more
- Published: May. 20, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-25089
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.... Read more
Affected Products : binisoft_windows_firewall_control- Published: Feb. 04, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40357
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection ... Read more
Affected Products : z-blogphp- Published: Sep. 20, 2022
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-29876
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all... Read more
- Published: Mar. 21, 2024
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2024-29937
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.... Read more
- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-2850
A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overf... Read more
- Published: Mar. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25302
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.... Read more
Affected Products : event_student_attendance_system- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-2556
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. It is possi... Read more
- Published: Mar. 17, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2022-40434
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.... Read more
Affected Products : softr- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-25350
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.... Read more
Affected Products : zoo_management_system- Published: Feb. 28, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2020-19692
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.... Read more
- Published: Apr. 04, 2023
- Modified: Aug. 12, 2025