Latest CVE Feed
-
9.8
CRITICALCVE-2024-24308
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirma... Read more
Affected Products : boostmyshop- Published: Feb. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24327
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.... Read more
- Published: Jan. 30, 2024
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2024-50486
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through 1.0.5.... Read more
Affected Products : flutter_api- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50487
Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.... Read more
Affected Products : maanstore_api- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2022-22522
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.... Read more
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24543
Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.... Read more
- Published: Feb. 05, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2024-5063
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injectio... Read more
Affected Products : online_course_registration_system- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24561
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() functio... Read more
Affected Products : vyper- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5084
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthen... Read more
Affected Products : hash_form- Published: May. 23, 2024
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2021-41609
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection... Read more
Affected Products : selectsurvey.net- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5117
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The manipulation of the argument username/password leads to sql injection. It is possible to... Read more
- Published: May. 20, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-25089
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.... Read more
Affected Products : binisoft_windows_firewall_control- Published: Feb. 04, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40357
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection ... Read more
Affected Products : z-blogphp- Published: Sep. 20, 2022
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-29876
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all... Read more
- Published: Mar. 21, 2024
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2024-29937
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.... Read more
- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-2850
A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overf... Read more
- Published: Mar. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25302
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.... Read more
Affected Products : event_student_attendance_system- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-2556
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. It is possi... Read more
- Published: Mar. 17, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2022-40434
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.... Read more
Affected Products : softr- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-25350
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.... Read more
Affected Products : zoo_management_system- Published: Feb. 28, 2024
- Modified: Mar. 27, 2025