Latest CVE Feed
-
9.8
CRITICALCVE-2022-40357
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection ... Read more
Affected Products : z-blogphp- Published: Sep. 20, 2022
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-29876
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all... Read more
- Published: Mar. 21, 2024
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2024-29937
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.... Read more
- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-2850
A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overf... Read more
- Published: Mar. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25302
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.... Read more
Affected Products : event_student_attendance_system- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-2556
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. It is possi... Read more
- Published: Mar. 17, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2022-40434
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.... Read more
Affected Products : softr- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-25350
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.... Read more
Affected Products : zoo_management_system- Published: Feb. 28, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2020-19692
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.... Read more
- Published: Apr. 04, 2023
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2024-25722
qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.... Read more
Affected Products : qanything- Published: Feb. 11, 2024
- Modified: Jun. 11, 2025
-
9.8
CRITICALCVE-2024-25935
Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9. ... Read more
Affected Products : registrationmagic- Published: Apr. 11, 2024
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2024-31094
Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. ... Read more
Affected Products :- Published: Mar. 31, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2799
A vulnerability, which was classified as problematic, has been found in cnoa OA up to 5.1.1.5. Affected by this issue is some unknown functionality of the file /index.php?app=main&func=passport&action=login. The manipulation leads to use of hard-coded pas... Read more
Affected Products : cnoa_oa- Published: May. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25826
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix th... Read more
Affected Products : opentsdb- Published: May. 03, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-28094
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.... Read more
- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6840
A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which cou... Read more
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-53909
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.... Read more
Affected Products : enterprise_vault- Published: Nov. 24, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2024-53910
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.... Read more
Affected Products : enterprise_vault- Published: Nov. 24, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2023-32306
Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker reports in versions prior to 1.22.13.5792. This was happening because the `reports.php` page was not validating all parameters in POST ... Read more
Affected Products : time_tracker- Published: May. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5519
A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack c... Read more
Affected Products : learning_management_system- Published: May. 30, 2024
- Modified: Feb. 11, 2025